EDBT 2026 Demo / reviewers in the wild / expert
Mohammad Zulkernine
dblp:45/1198
· DBLP profile ↗
143ranked-venue papers
6as first author
40since 2021 · last 2026
0000-0003-1697-4101ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 50 · 2 first-author · 15 since 2021Software engineering, systems software and programming languages · 49 · 3 first-author · 8 since 2021Applied, interdisciplinary, general and emerging computing · 32 · 1 first-author · 9 since 2021Computer networks · 25 · 10 since 2021Systems, architecture and hardware · 6 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 2Theory of computation · 2 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Autonomous and Adaptive Cyber Incident Detection and Response in Industrial Cyber-Physical Systems Using Hierarchical Reinforcement LearningabstractCyber-Physical Systems (CPSs) are the backbone of many critical infrastructures. However, they have introduced an uncharted territory of security vulnerabilities and attack vectors, mainly due to the deeply integrated physical and cyber spaces. Moreover, in industrial CPS settings, network openness exposes the system to the outside world and renders it vulnerable to cyber threats. The security of industrial CPS significantly relies on the cyber incident detection and response systems which are fundamental to ensure the continuous and proper operation of cyber-physical processes. Among the key configuration parameters of these defense systems is the detection threshold. However, finding the optimal threshold that strikes the right balance between missed detection and false-positive rates remains a challenging problem. In this article, we propose a novel approach that leverages a Hierarchical Reinforcement Learning (HRL) architecture to autonomously detect the dynamic instability in an industrial CPS network and respond by adapting the cyber incident detection and response threshold range to minimize the effects of possible incidents. We developed and tested four HRL algorithmic variants, each offering potential avenues for optimization with its own strengths and limitations. Our agents dynamically select these ranges by assessing the expected risk and potential damage over time. In addition, the agent’s selection process aims to minimize false positives and reduce the cost associated with changing the selected range. All four algorithmic adaptations show the effectiveness of HRL for designing adaptive cyber-physical defense compared to static approaches. Our experimental results indicate that our proposed technique is effective for building autonomous cyber incident detection systems in industrial CPS. Ayesha Babar, Talal Halabi, Mohammad Zulkernine |
ACM Trans. Cyber Phys. Syst. | 3 |
| 2026 | Bridging Black-Box and No-Box: Embedding Reconstruction Attacks on Deep Recognition SystemsabstractDeep Neural Network (DNN)-based recognition systems are widely deployed for face and speaker authentication, yet remain vulnerable to Embedding Reconstruction Attacks (ERAs), in which adversaries recover biometric data from embeddings. Prior work assumes white-box or black-box access, requiring stronger adversarial knowledge than many real-world deployments provide. We introduce the first ERA framework that systematically characterizes settings withlessknowledge than black-box access. Our four-tier taxonomy progressively reduces adversarial capabilities, ranging from score-only and decision-only interfaces to no-query/no-feedback scenarios, mirroring the spectrum of commercial recognition APIs. To conduct ERAs under these constraints, we design high-fidelity reconstructors using Stable Diffusion for faces and flow-matching transformers for voices, trained via adaptive knowledge distillation. We formalize per-tier feasibility, proving Tiers 1–3 are practically exploitable and Tier 4 is infeasible under our formal threat model. Experiments on face and voice benchmarks show that our methods outperform existing black-box attacks under identical query budgets, achieving 93.27%, 82.60%, and 62.29% success rates for Tiers 1–3, respectively. We further evaluate compressed DNNs (pruned, quantized, and distilled models), providing the first systematic evidence that restricted-access recognition models remain at high risk in production. Qi Li 0033, Jianbing Ni, Mohammad Zulkernine, Rongxing Lu |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | ARC-CBDC: Enhancing Anonymity and Regulatory Compliance in Central Bank Digital CurrencyabstractIn this paper, we propose a novel Central Bank Digital Currency (CBDC) system based on a two-tier architecture, named ARC-CBDC, where the central bank issues digital currency to commercial banks, which in turn manage transactions among anonymous users throughout the currency's lifecycle. Unlike existing systems that offer only conditional anonymity, ARC-CBDC extends traditional electronic cash to provide full user anonymity, even against commercial banks, despite their ability to observe coin accumulation during withdrawals and reductions during deposits. By utilizing BBS+ signatures, users can open bank accounts, withdraw coins, and deposit received coins without revealing their real identities. A distinctive feature of ARC-CBDC is that commercial banks are allowed to modify a recorded transaction only once within a permissioned blockchain shared between the central bank and participating commercial banks. As the trusted authority, the central bank handles coin issuance and enforces financial regulations. To prevent double spending, the central bank performs batch verification of transactions, enabling efficient detection and tracing of double-spent coins. ARC-CBDC is specifically designed with CBDC architectural requirements in mind, introducing novel mechanisms to support strong anonymity and full traceability. Through formal security proofs and performance analysis, we demonstrate that the security of ARC-CBDC relies on standard cryptographic assumptions and that it is both efficient and practical, suitable for implementation on a range of devices, including laptops and mobile phones. Yunke Liu, Jianbing Ni, Mohammad Zulkernine |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | CSA-SACS: A Framework for Comparative Security Assessment in Smart Aging Care SystemsabstractSmart Aging Care Systems (SACS) for independent living relies on various IoT service products to support the well-being of older adults. While research in this domain emphasizes the necessity of robust security protocols to protect this vulnerable population from cyber threats, there is a critical gap in methodologies for selecting the most suitable alternatives that meet the security requirements of SACS. This research introduces a framework, called Comparative Security Assessment in SACS (CSA-SACS). CSA-SACS evaluates the security standards of service products within SACS, integrating perspectives from multiple decision-makers, such as usability engineers and security experts. To address these evaluations’ inherent uncertainty and subjectivity, fuzzy triangular numbers are used for comparative assessments. The evaluation criteria are derived from the very recent ISO/IEC 25010:2023 standard, which encompasses conflicting elements, making the Analytic Hierarchy Process (AHP) a suitable approach for prioritization and ensuring consistency in decision-making. CSA-SACS enables evaluators to prioritize security selection criteria based on SACS-specific requirements and an automated error-handling mechanism to improve the reliability of judgment aggregation. Nilesh Chakraborty, Shahrear Iqbal, Mohammad Zulkernine |
COMPSAC | 3 |
| 2025 | Is Your PIN Safe Against Advanced Human-Centric Shoulder Surfing?abstractPersonal Identification Numbers (PINs) are a widely used authentication method, especially in systems with limited user input interfaces. Although numerous studies have investigated the vulnerabilities of PINs against various cyber threats, some attacks, such as basic shoulder surfing, are often mitigated by enhancing the complexity of the user-interface. This paper challenges that conventional approach by introducing an attack strategy that builds upon three basic classifiers−Decision Tree, Random Forest, and Naive Bayes. Through the examination of both four-digit and six-digit PINs, the findings reveal that even with only partial knowledge of a captured PIN sequence−due to the cognitive limitations of human adversaries−it is possible to predict the remaining digits of the PIN with a significant success rate. In some cases, this rate exceeds 50%, which is considerably higher than the 10% success rate expected from random guessing. Despite the diminished effectiveness of the proposed attack model for six-digit PINs, the results of this preliminary research are compelling enough to question the assumed ineffectiveness of Human-Centric Shoulder Surfing (HCSS). Nilesh Chakraborty, Mohammad Zulkernine |
COMPSAC | 2 |
| 2025 | Novel Norms for Pruning Convolutional Neural NetworksabstractConvolutional Neural Networks (CNNs) for object detection in images can have millions of parameters, leading to a large memory footprint and long inference times. These parameters are grouped into objects called filters. Structured pruning is the process of removing some proportion of these filters in a CNN without significantly reducing its accuracy. The manner in which filters are chosen affects the performance of the model. One method for selecting which filters to prune is to use a norm function to assign a numeric value to each filter and prune the ones with the smallest values. Existing works only use a handful of norms for pruning. In this work, we evaluate the effectiveness of a wide range of norms for pruning, including novel norms that we have developed. We compare the results of our evaluation and show that our norms are more effective for pruning than conventional norms for the YOLOv10n model. Our methods for evaluating norms can be used by researchers with other models they may wish to evaluate, and with the norms discussed in this paper as well as norms they may define themselves. Abrar Kazi, M. Anwar Hossain 0005, Mohammad Zulkernine |
COMPSAC | 3 |
| 2025 | CAGAID: Context-Aware Gait Anomaly-Based Intrusion Detection
Youssef Yamout, Shahrear Iqbal, Mohammad Zulkernine |
CRiSIS | 3 |
| 2025 | LIDIT: Low-Latency Intrusion Detection in IoMT Devices using TinyMLabstractThe Internet of Medical Things (IoMT) is reshaping healthcare by facilitating real-time monitoring, diagnosis, and treatment through interconnected devices and systems. However, the proliferation of resource-constrained IoMT devices introduces substantial cybersecurity challenges. Due to limited computational and energy resources, conventional security mechanisms such as complex encryption algorithms and robust firewalls are often infeasible. This poses serious risks in critical healthcare applications where delayed threat detection can lead to life-threatening outcomes. To address these pressing challenges, this research presents LIDIT, a novel anomaly-based intrusion detection framework with specialized feature segmentation designed for resource-constrained environments using TinyML. Our approach employs a multi-branch LSTM-autoencoder model trained exclusively on benign traffic, utilizing an input segmentation strategy based on session-level, TCP flags, and time-window features to capture fine-grained temporal as well as contextual patterns in network behavior. We evaluated the model on the CICIoMT2024 and IoMT-TrafficData dataset and demonstrated that our proposed segmentation framework improves anomaly detection performance over unified models. The best-performing model achieved an accuracy of 0.9990 and an F1-score of 0.9988 with a recall of 0.9995 for the CICIoMT2024 dataset. Post-training quantization using FLOAT16 and INT8 further significantly reduced the model sizes, making it suitable for real-time deployment. The system was successfully deployed on a Raspberry Pi Zero 2 W and tested under a live SYN flood attack, detecting anomalies in real time with an average inference time of 10.25 milliseconds. These results confirm the effectiveness, efficiency, and deployability of LIDIT as a lightweight, low-latency intrusion detection solution for modern healthcare IoT systems. Shaila Tajmim Anuva, Shahrear Iqbal, Mohammad Zulkernine |
GLOBECOM | 3 |
| 2025 | HyFIDS: Hybrid Frequency-Aware Lightweight Intrusion Detection for Internet of VehiclesabstractIntrusion Detection Systems (IDSs) play a crucial role in the Internet of Vehicles (IoV) by safeguarding against reliability and security threats arising from the growing complexity and interconnectivity. However, existing deep learning (DL)-based IDSs, particularly those relying on resource-intensive architectures, often fail to meet the limited computational resource constraints of IoV gateways and tend to overlook real-world deployment considerations. To address these challenges, we propose HyFIDS, a hybrid frequency-aware lightweight intrusion detection system, for IoV ecosystems. HyFIDS integrates raw packet representations with frequency-domain representations through a novel frequency-aware module. This design enables HyFIDS to extract temporal and spectral features of both CAN frames and IP packets, thereby enhancing representational efficiency while maintaining computational lightweightness. To validate its performance, we implement HyFIDS on four benchmark datasets encompassing both inter-vehicle and intra-vehicle scenarios. Extensive experiments demonstrate that HyFIDS achieves a high detection accuracy of 99.98%, maintains a lightweight model with only 20K MACs, and obtains the highest throughput of 8.9 Mbps. Zeling Zhang, Jianbing Ni, Mohammad Zulkernine |
GLOBECOM | 4 |
| 2025 | SRED: Secure and Robust Emotion Detection for Advanced Driver Assistance Systems
Nadia Rubaiyat, Jianbing Ni, Mohammad Zulkernine |
GLOBECOM | 3 |
| 2025 | Robustness Assessment and Enhancement of Text Watermarking for Google's SynthIDabstractRecent advances in LLM watermarking methods such as SynthID-Text by Google DeepMind offer promising solutions for tracing the provenance of AI-generated text. However, our robustness assessment reveals that SynthID-Text is vulnerable to meaning-preserving attacks, such as paraphrasing, copy-paste modifications, and back-translation, which can significantly degrade watermark detectability. To address these limitations, we propose SynGuard, a hybrid framework that combines the semantic alignment strength of Semantic Invariant Robust (SIR) with the probabilistic watermarking mechanism of SynthID-Text. Our approach jointly embeds watermarks at both lexical and semantic levels, enabling robust provenance tracking while preserving the original meaning. Experimental results across multiple attack scenarios show that SynGuard improves watermark recovery by an average of 11.1% in F1 score compared to SynthID-Text. These findings demonstrate the effectiveness of semantic-aware watermarking in resisting real-world tampering. All code, datasets, and evaluation scripts are publicly available at: https://github.com/githshine/SynGuard. Xia Han, Qi Li 0033, Jianbing Ni, Mohammad Zulkernine |
TrustCom | 4 |
| 2025 | Detecting Intrusions in CBTC Systems with Mixed-Mode OperationsabstractCommunication-Based Train Control (CBTC) systems are automatic train control systems that rely on wireless data transmissions to provide safe and efficient railway operations. However, integrating wireless technologies has rendered railways vulnerable to cyber attacks. The current body of research concerning CBTC security does not consider that most railway operators deploy this system alongside a secondary train control system, known as external interlocking. The integration of these two train control systems allows for the operation of both CBTC-capable and CBTC-incapable trains along the same railway. This integration is termed a mixed-mode operation in the IEEE 1474.1 standard for CBTC performance and functional requirements. This work proposes a machine learning-based intrusion detection system for wireless communications in mixedmode operations to address the aforementioned gap in the literature. The detection methods proposed in this work were evaluated in a simulated railway environment that integrated the CBTC system with an external interlocking. Multiple machine learning models have been trained on the resultant data transmissions of both systems under normal and attack conditions. The experimental results provide valuable insights into which models can best meet the requirements of an integrated CBTC-external interlocking railway to ensure the integrity and availability of wireless transmissions. Mackenzie Tummers, Amin Fakhereldine, Mohammad Zulkernine |
VTC2025-Spring | 3 |
| 2025 | An anomaly detection based approach for continuous authentication with smartwatch inertial sensors
Arash Gholami, Furkan Alaca, Mohammad Zulkernine |
Comput. Secur. | 3 |
| 2025 | IPRPAS: A Dataset of Physical Adversarial Samples for Assessing Object Detection in Intelligent Vehicles
Mahdieh Safarzadehvahed, Mohammad Zulkernine, Paulo Ricardo Marques de Araujo, Sidney Givigi |
IEEE Internet Things J. | 2 |
| 2025 | NeuroYara: Learning to Rank for Yara Rules Generation Through Deep Language Modeling and Discriminative N-Gram EncodingabstractSignature-based malware detection methods are recognized for their simplicity, explainability, and efficiency. One of the most commonly used tools is Yara, which provides the syntax for crafting malware signatures. However, while developing high-quality Yara rules requires significant expertise in malware analysis, training such skilled analysts can be both resource-intensive and time-consuming. While a few works have been conducted to automate the generation of signatures, signatures generated by those works typically underperform the manually generated ones. In addition, these automated methods often depend on large static databases of hard-coded byte n-grams to minimize false positives. Instead of storing a large non-inclusive database to score byte n-grams, we propose a novel architecture utilizing two learning to rank neural networks to understand the underlying effectiveness and correlations among n-grams extracted for rule construction. This approach provides better flexibility and coverage of possible n-grams while reducing the required storage size from several GBs to only 10MBs. Combining these two models with a hierarchical density-based clustering method allows us to group multiple n-grams into logical conditions as Yara rules of higher quality. Experimental results show that our framework, NeuroYara, reduces the resources invested by analysts while generating rules with a low false-positive rate outperforming existing tools and manually-generated rules. Ziad Mansour, Weihan Ou, Steven H. H. Ding, Mohammad Zulkernine, Philippe Charland |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | PulseAnomaly: Unsupervised Anomaly Detection on Avionic Platforms With Seasonality and Trend Modeling in Transformer NetworksabstractFor communication within military avionic platforms (e.g., F-15 and F-35), the US Department of Defense established MIL-STD-1553 military standard. It has been released for more than 50 years and is still used in platforms other than military avionics. It was originally produced to be used with military avionics, but in the following decades, it was adopted into all branches of the armed forces, as well as spacecraft and commercial avionics. However, potential attacks against the MIL-STD-1553 may exist due to the demand for internet communication between planes and the lack of security. The current study presentsPulseAnomaly, a novel unsupervised anomaly detection model for the MIL-STD-1553 bus that utilizes time-feature and message sequences. Our model demonstrates better performance compared to baseline models in the test, achieving a higher F1-score and showing excellent AUROC compared to existing methods. Additionally, we have used data from a recently developed open-source MIL-STD-1553 real-time bus simulator, which features a more diverse range of attacks and data points that more closely resemble real-world scenarios. Evaluation results show that our model outperforms existing unsupervised solutions. Hanbo Yu, Sudipta Acharya, Steven H. H. Ding, Mohammad Zulkernine |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2024 | Generative Adversarial Networks for Robust Anomaly Detection in Noisy IoT EnvironmentsabstractThe Internet of Things (IoT) enables us to collect and process vast amounts of data in real time. However, the security of IoT devices and networks is highly susceptible to cyber attacks that threaten data integrity and service availability. Furthermore, due to the diverse nature of data collected from numerous nodes in IoT systems and the disturbances occurring within them, detecting anomalous activities and compromised nodes is considerably more challenging than in conventional computer systems. Therefore, it is crucial to develop robust and dependable anomaly detection methods to identify and remove malicious and/or unwanted data, which ensures their exclusion from IoT-powered applications and data analytics. To achieve this, this paper proposes a Generative Adverserial Networks (GAN)-based anomaly detection for IoT systems. The proposed model enables the autoencoder - using the adversarial training of GAN - to learn a better representation of IoT data, making it robust against noisy and changing environments. Based on experiments with real-world IoT datasets, the proposed framework has shown to improve the accuracy of detecting malicious traffic in IoT and surpass state-of-the-art anomaly detection models. Adel Abusitta 0001, Talal Halabi, Ahmed Saleh Bataineh, Mohammad Zulkernine |
ICC | 4 |
| 2024 | Building Secure Software for Smart Aging Care Systems: An Agile ApproachabstractThere exists a persistent challenge in sufficiently addressing software security issues and effectively integrating security procedures into the software development life cycle. Software products vulnerable to security threats can result in severe consequences, especially in sensitive domains like those providing age-related support for older adults. This work offers guidelines to address software vulnerabilities in one of such evolving and sensitive domains, namely, Smart Aging Care Systems (SACS). The existing guidelines for securing the software cannot effectively address the observed vulnerabilities in SACS because of the unique demographics of its users and special design requirements. Therefore, the primary objective of this paper is to enhance the comprehension of secure software development methods, considering best security practices or controls in general and tailoring their selection based on the unique requirements of SACS. The chosen controls are then reshaped to align with the specific needs of SACS, with implementation carried out using the agile framework, specifically Scrum. We believe that this work will aid software development organizations in significantly enhancing the security of their software products for SACS dynamically and effectively, leveraging the Scrum framework, and also inspire its implementation in other emerging domains. Nilesh Chakraborty, Shahrear Iqbal, Mohammad Zulkernine |
QRS | 3 |
| 2024 | Gait4Auth: Enhancing Identification and Security in Gait-Based Authentication
Youssef Yamout, Shahrear Iqbal, Nilesh Chakraborty, Mohammad Zulkernine |
SecureComm (4) | 4 |
| 2024 | Pulse-to-Pair: Heartbeat-Based Authentication of IoT Devices for Elderly Care
Tashaffi Samin Yeasar, Shahrear Iqbal, Mohammad Zulkernine |
SecureComm (4) | 3 |
| 2024 | VeriBin: A Malware Authorship Verification Approach for APT Tracking through Explainable and Functionality-Debiasing Adversarial Representation LearningabstractMalware attacks are posing a significant threat to national security, cooperate network, and public endpoint security. Identifying the Advanced Persistent Threat (APT) groups behind the attacks and grouping their activities into attack campaigns help security investigators trace their activities thus providing better security protections against future attacks. Existing Cyber Threat Intelligent (CTI) components mainly focus on malware family identification and behavior characterization, which cannot solve the APT tracking problem: while APT tracking needs one to link malware binaries of multiple families to a single threat actor, these behavior or function-based techniques are tightened up to a specific attack technique and would fail on connecting different families. Binary Authorship Attribution (AA) solutions could discriminate against threat actors based on their stylometric traits. However, AA solutions assume that the author of a binary is within a fixed candidate author set. However, real-world malware binaries may be created by a new unknown threat actor. To address this research gap, we propose VeriBin for the Binary Authorship Verification (BAV) problem. VeriBin is a novel adversarial neural network that extracts functionality-agnostic style representations from assembly code for the AV task. The extracted style representations can be visualized and are explainable with VeriBin’s multi-head attention mechanism. We benchmark VeriBin with state-of-the-art coding style representations on a standard dataset and a recent malware-APT dataset. Given two anonymous binaries of out-of-sample authors, VeriBin can accurately determine whether they belong to the same author or not. VeriBin is resilient to compiler optimizations and robust against malware family variants. Weihan Ou, Steven H. H. Ding, Mohammad Zulkernine, Li Tao Li, Sarah Labrosse |
ACM Trans. Priv. Secur. | 3 |
| 2023 | The Ultimate Battle Against Zero-Day Exploits: Toward Fully Autonomous Cyber-Physical DefenseabstractThe last decade has shown that networked cyber-physical systems (NCPS) are the future of critical infrastructure such as transportation systems and energy production. However, they have introduced an uncharted territory of security vulnerabilities and a wider attack surface, mainly due to network openness and the deeply integrated physical and cyber spaces. On the other hand, relying on manual analysis of intrusion detection alarms might be effective in stopping run-of-the-mill automated probes but remain useless against the growing number of targeted, persistent, and often AI-enabled attacks on large-scale NCPS. Hence, there is a pressing need for new research directions to provide advanced protection. This paper introduces a novel security paradigm for emerging NCPS, namely Autonomous Cyber-Physical Defense (ACPD). We lay out the theoretical foundations and describe the methods for building autonomous and stealthy cyber-physical defense agents that are able to dynamically hunt, detect, and respond to intelligent and sophisticated adversaries in real time without human intervention. By leveraging the power of game theory and multi-agent reinforcement learning, these self-learning agents will be able to deploy complex cyber-physical deception scenarios on the fly, generate optimal and adaptive security policies without prior knowledge of potential threats, and defend themselves against adversarial learning. Nonetheless, serious challenges including trustworthiness, scalability, and transfer learning are yet to be addressed for these autonomous agents to become the next-generation tools of cyber-physical defense. Talal Halabi, Mohammad Zulkernine |
SSE | 2 |
| 2023 | Attack Endgame: Proactive Security Approach for Predicting Attack Consequences in VANETabstractIn the fast dynamic environment of Vehicle Ad Hoc Networks (VANETs), proactive security measures are necessary. Reactive security has been VAVNETs' guardian angel for some time, but now it is insufficient against current security attacks. Attack prediction is a promising solution capable of keeping up with the recent cyber security challenges. First, we need to understand where prediction fits in the attack process. To accomplish this, we introduce an attack life cycle in a VANET and exploit the proactive and retroactive phases. One of the proactive phases is the after-effect of the attack or what we call attack endgame. We use the Framework for Misbehavior Detection (F2MD) to simulate an attack effect with adverse side effects on road traffic. We implement traffic warning messages in F2MD. Then, we create attacks on these messages, namely “fake accident”, and simulate the effect of these attacks on the vehicles while capturing the results using F2MD. We simulate the impact of acting on these messages or the attack endgame, which manifested in creating hazards. We use Recurrent Neural Network (RNN) models to predict the endgame of the fake accident attack on the road. We experiment with vanilla artificial neural network solutions to create a baseline. Afterward, we use Long Short-Term Memory (LSTM) and Gated Recurrent Units (GRU) to build a stacked RNN model to predict the attack endgame at different time windows. They effectively predict the occurrence of a hazard up to 3.5 minutes ahead with over 80% accuracy. Mohammed A. Abdelmaguid, Hossam S. Hassanein, Mohammad Zulkernine |
ICC | 3 |
| 2023 | A VeReMi-based Dataset for Predicting the Effect of Attacks in VANETsabstractVehicular Ad Hoc Networks (VANETs) have received considerable attention because of their potential to improve road safety. However, reactive security approaches in VANETs are of concern; thus, proactive security is needed to prevent cyberattacks. The current VANET datasets are limited in their ability to evaluate proactive security approaches, limiting research in this area. This paper presents a VeReMi-based dataset named VeReMi for Attack Prediction (VeReMiAP). Developed from the Framework For Misbehavior Detection (F2MD). VeReMiAP incorporates three key elements: Cooperative Awareness Messages (CAMs), a new class of attacks known as Fake Reporting Attacks, and an evaluation of the impact of this attack, which in this case manifests as a road hazard. The ripple effect of this attack goes beyond the targeted vehicle, making it a threat to the overall security and reliability of VANETs. The VeReMiAP dataset evaluates cyberattack prediction techniques and generates countermeasure solutions for VANET attacks. To test the dataset, we conducted a temporal analysis to observe the effect of the attack on velocity and a geospatial analysis to enhance our understanding of the spatial distribution of hazards within the road network. Results show that VeReMiAP is a potential tool to advance security research in VANETs. Mohammed A. Abdelmaguid, Hossam S. Hassanein, Mohammad Zulkernine |
MSWiM | 3 |
| 2023 | AIM: An Android Interpretable Malware detector based on application class modeling
Farnood Faghihi, Mohammad Zulkernine, Steven H. H. Ding |
J. Inf. Secur. Appl. | 2 |
| 2022 | SAMM: Situation Awareness with Machine Learning for Misbehavior Detection in VANETabstractVehicular Ad hoc Network (VANET) is a foundation stone for connected vehicles. As vehicles’ safety depends heavily on the exchanged data’s accuracy, VANET has a low tolerance for false data. The process of intentionally exchanging inaccurate data is called misbehaving. Machine learning (ML)-based solutions were heavily invested in detecting misbehavior messages. However, they also have some limitations with respect to how much they can detect. To overcome such limitations, we introduce situation awareness (SA) as a powerful concept that can break the limits of the used ML models, leading to more accurate and reliable solutions. Situation awareness uses environmental elements and events to gain a holistic view of the system at any given time. In this paper, we propose using SA to predict the trust of the surrounding cars and consequently reevaluate the outcome of the used ML model. Based on the collected data and SA information, we may reject a message classified as benign by the ML model or vice versa. We used VeReMi dataset to evaluate the proposed approach called SAMM (Situation Awareness with Machine Learning for Misbehavior Detection in VANET) on different ML models with a wide range of features. The results show that the proposed approach improves the system’s accuracy for various misbehavior attacks by enhancing the recall rate up to 24% and 50% in some cases. Mohammed A. Abdelmaguid, Hossam S. Hassanein, Mohammad Zulkernine |
ARES | 3 |
| 2022 | Message from the Standing Committee Vice ChairsabstractOn behalf of the COMPSAC 2021 organization we would like to welcome you to the 46th Annual IEEE International Computers, Software, and Applications Conference (COMPSAC 2022), June 26-July 1, 2022. COMPSAC, the IEEE Computer Society Signature Conference on Computers, Software, and Applications, was first held in 1977 in Chicago. In the years since its founding, it has become one of the major international forums for academia, industry, and government to discuss research results, advancements and future trends in computer and software technologies and applications. The technical program includes research papers, research and industry panel discussions, fast abstracts, student research symposiums, and workshops on emerging important topics. It now alternates its meeting among sites in Asia, Europe, and North America. Over the years, its meetings have advanced the major topics in computing and software development. But, for 2020-2022, we are having COMPSAC virtually due to the global COVID-19 pandemic. The theme of COMPSAC 2022 is “Intelligent and Resilient Computing for a Collaborative World”. It supports research and development of general methodology for data driven intelligence, digital transformation and a consideration of emerging applications for deployment, including Smart Health devices, networked healthcare, wearable computing, internet-of-things, cyber-physical systems, smart cities, and smart planet. Sheikh Iqbal Ahamed, Mohammad Zulkernine |
COMPSAC | 2 |
| 2022 | Detecting Intrusions in Communication-Based Train Control SystemsabstractCommunication-Based Train Control (CBTC) systems are being widely used as a control and signalling system for railways. They allow trains to communicate with infrastructural components through wireless communications to receive operational commands, and to include Ethernet-based communications inside them to perform traction and braking operations. These communication technologies make railway systems vulnerable to cyber-attacks that can disrupt traction and braking operations and threaten trains’ safety. Attacks can take place without the driver noticing, which might lead to collisions. In this work, we propose an Intrusion Detection System (IDS) based on Machine Learning (ML) to detect attacks on traction and braking operations performed inside the train. This IDS analyzes trains’ mobility data and classifies them into normal and attack data. No previous work proposed an IDS to detect attacks on trains’ mobility. Therefore, the proposed IDS helps train control centers to detect such attacks and take appropriate measures to avoid hazardous incidents. To evaluate this system, a realistic network of trains was simulated using Simulation of Urban MObility (SUMO) on part of the railway in Berlin, Germany. We compared the performance of three ML classifiers: K-Nearest Neighbours, Naive Bayes and Random Forests. The results show that Random Forests performed the best with a classification accuracy between 94% and 99%. Additionally, three plausibility checks were proposed to enhance the detection accuracy by 1% to 3%. Amin Fakhereldine, Mohammad Zulkernine, Dan Murdock |
ICC | 2 |
| 2022 | AT-CBDC: Achieving Anonymity and Traceability in Central Bank Digital CurrencyabstractIn this paper, we propose a new central bank digital currency (CBDC) system based on the two-tier architecture. The proposed system enhances the traditional bank-user framework of electronic cash and employs the commercial banks for account and coin management. The coin splitting is supported during coin withdrawal of users and the coin combination is achieved for coin deposit at the commercial banks, such that the efficiency of coin management is improved. The other distinguished feature is that the proposed system achieves the anonymity against the commercial banks, while enabling the central bank to support user tracing and double-spending prevention. Specifically, by utilizing the BBS+ signatures, the users can create bank accounts, withdraw coins, and deposit the received coins at the commercial banks without exposing their real identities. As a trusted party, the central bank is responsible for money issuing and financial regulation. In addition, to ensure the system inclusive, users can receive payments from others even they do not have bank accounts at commercial banks. Finally, we demonstrate that the proposed system achieves the desirable properties of balance, anonymity, and traceability and show the efficiency and practicality for the implementation on mobile devices. Yunke Liu, Jianbing Ni, Mohammad Zulkernine |
ICC | 3 |
| 2022 | SAS-GKE: A Secure Authenticated Scalable Group Key ExchangeabstractSecure group communication is one of the challenging issues of present times. With the advancements of the cloud technologies and the internet services, people are getting more dependent on multi-party services, such as online meetings and classes, video and audio group calling and messaging, online conferences and webinars, and online gaming. To secure these multi-party communications, one of the most important components is the group key exchange (GKE). The existing GKE approaches are computationally expensive and do not offer scalability. These approaches only support small static groups to share a common secret key and do not properly address the situation of adding or removing group member(s). This is not acceptable for the multi-party communications with a large number of participants, especially when any participant(s) can join or leave the communications at any time. In this paper, we propose a secure, authenticated, and scalable group key exchange (SAS-GKE) that implements a constant-round contributory approach to generate the common secret key between any number of participants. SAS-GKE arranges all the participants in a three-tiered (depth = 2) m-ary tree structure that distributes the computational load between the participants in a balanced way. The proposed GKE utilizes public key authentication that prevents man-in-the-middle (MITM) attacks at every step of the group key exchange. Abu Faisal, Mohammad Zulkernine |
QRS | 2 |
| 2022 | Classification-Based Anomaly Prediction in XACML Policies
Maryam Davari, Mohammad Zulkernine |
SecureComm | 2 |
| 2022 | CamoDroid: An Android application analysis environment resilient against sandbox evasion
Farnood Faghihi, Mohammad Zulkernine, Steven H. H. Ding |
J. Syst. Archit. | 2 |
| 2022 | OD1NF1ST: True Skip Intrusion Detection and Avionics Network Cyber-attack SimulationabstractMIL-STD-1553 is a communication bus that has been used by many military avionics platforms, such as the F-15 and F-35 fighter jets, for almost 50 years. Recently, it has become clear that the lack of security on MIL-STD-1553 and the requirement for internet communication between planes has revealed numerous potential attack vectors for malicious parties. Prevention of these attacks by modernizing the MIL-STD-1553 is not practical due to the military applications and existing far-reaching installations of the bus. We present a software system that can simulate bus transmissions to create easy, replicable, and large datasets of MIL-STD-1553 communications. We also propose an intrusion detection system (IDS) that can identify anomalies and the precise type of attack using recurrent neural networks with a reinforcement learning true-skip data selection algorithm. Our IDS outperforms existing algorithms designed for MIL-STD-1553 in binary anomaly detection tasks while also performing attack classification and minimizing computational resource cost. Our simulator can generate more data with higher fidelity than existing methods and integrate attack scenarios with greater detail. Furthermore, the simulator and IDS can be combined to form a web-based attack-defense game. Michael Wrana, Marwa Elsayed, Karim Lounis, Ziad Mansour, Steven H. H. Ding, Mohammad Zulkernine |
ACM Trans. Cyber Phys. Syst. | 6 |
| 2022 | AdaptIDS: Adaptive Intrusion Detection for Mission-Critical Aerospace VehiclesabstractAerospace and defense industries are particularly vulnerable to cyber threats given their sensitive nature, significantly extending the consequences of security breaches to the national level. Aerospace vehicles are augmented by cooperative control, intelligent, connected, and autonomous systems. The risk against such systems is further amplified due to commonly relying on the MIL-STD-1553 communication bus developed with a high focus on reliability and fault tolerance, albeit with security as a second priority. MIL-STD-1553 (a.k.a., STANAG 3838 by NATO) is a standard that describes a serial data communication bus primarily used in aerospace vehicles for military and civilian applications, including avionics, aircraft, and spacecraft data handling. In the absence of core security measures such as authentication, authorization, and encryption, the bus connecting sensitive functions, including autopilot, GPS, fuel valve switches, and other avionics equipment, is easily vulnerable to a wide range of attacks. This paper proposes, AdaptIDS, a novel adaptive intrusion detection system as a security analytics framework for the MIL-STD-1553 communication bus. AdaptIDS mainly adopts data science principles and leverages advanced deep learning techniques (i.e., the stacking ensemble) to boost its generalization capabilities for detecting unseen patterns of attacks in the dynamic changing environment of aerospace vehicles. Extensive experiments are conducted using two datasets generated from an open-source simulation system, reflecting dynamic real-life scenarios. The evaluation results demonstrate that our solution outperforms existing solutions with high detection effectiveness of 0.99 F1-measure and computational time efficiency. Marwa Elsayed, Michael Wrana, Ziad Mansour, Karim Lounis, Steven H. H. Ding, Mohammad Zulkernine |
IEEE Trans. Intell. Transp. Syst. | 6 |
| 2021 | Policy Modeling and Anomaly Detection in ABAC Policies
Maryam Davari, Mohammad Zulkernine |
CRiSIS | 2 |
| 2021 | AVSDA: Autonomous Vehicle Security Decay Assessment
Lama Moukahal, Mohammad Zulkernine, Martin Soukup |
CRiSIS | 2 |
| 2021 | RansomCare: Data-centric detection and mitigation against smartphone crypto-ransomware
Farnood Faghihi, Mohammad Zulkernine |
Comput. Networks | 2 |
| 2021 | A security pattern detection framework for building more secure software
Aleem Khalid Alvi, Mohammad Zulkernine |
J. Syst. Softw. | 2 |
| 2021 | Protecting the Internet of Vehicles Against Advanced Persistent Threats: A Bayesian Stackelberg GameabstractConnected vehicles are essential for the deployment of intelligent transportation services. However, the high level of connectivity in today's Internet of vehicles (IoV) and the extreme reliance on the data collected from the smart transportation infrastructure widen the space of security vulnerabilities, making the IoV a potential target for cyberattacks. This article investigates novel sophisticated ways to exploit the IoV and launch intelligent attacks on road traffic services by creating persistent impact and reducing detection chances. This article models the processes of attack and defense as a cybersecurity Stackelberg game leading to optimal mixed strategies for both the attackers and the IoV defense system, where the latter optimally deploys the available security resources within the transportation infrastructure to minimize the impact of attacks and improve their detection. The game is of Bayesian type and considers several types of data corruption attacks that occur according to a probability distribution that we determine based on a rigorous risk assessment approach. The results show that our game model and solution allow us to reduce the impact of advanced persistent threats compared to a uniform defense design that is indifferent to attackers' strategies and types. The solution could be integrated into the design of IoV intrusion detection systems to increase their robustness. Talal Halabi, Omar Abdel Wahab 0001, Ranwa Al Mallah, Mohammad Zulkernine |
IEEE Trans. Reliab. | 4 |
| 2021 | Vulnerability-Oriented Fuzz Testing for Connected Autonomous Vehicle SystemsabstractIn an era of connectivity and automation, the vehicle industry is adopting numerous technologies to transform driver-centric vehicles into intelligent mechanical devices driven by software components. Software integration and network connectivity inherit numerous security issues that open the door for malicious attacks. Software security testing is a scalable and practical approach to identify systems’ weaknesses and vulnerabilities at an early stage and throughout their life-cycle. Security specialists recommend fuzz testing to identify vulnerabilities within vehicle software systems. Nevertheless, the randomness and blindness of fuzzing hinder it from becoming a reliable security tool. This article presents a vulnerability-oriented fuzz (VulFuzz) testing framework that utilizes security vulnerability metrics designed particularly for connected and autonomous vehicles to direct and prioritize the fuzz testing toward the most vulnerable components. While most gray-box fuzzing techniques aim solely to expand code coverage, the proposed approach assigns weights to ensure a thorough examination of the most vulnerable components. Moreover, we employ an input structure-aware mutation technique that can bypass vehicle software systems’ input formats to boost test performance and avoid dropped test cases. Such a testing technique will contribute to the quality assurance of vehicle software engineering. We implemented the proposed approach on OpenPilot, a driver assistance system, and compared our results to American fuzzy lop (AFL) and an unguided mutation-based fuzzer. Within 16.8 h, VulFuzz exposed 335 crashes, 41 times more than AFL and two times more than an unguided mutation-based fuzzer. VulFuzz is explicitly efficient for automotive systems, reaching the same code coverage as AFL but with more exposed crashes and fewer dropped messages. Lama Moukahal, Mohammad Zulkernine, Martin Soukup |
IEEE Trans. Reliab. | 2 |
| 2020 | Frequency Hopping Spread Spectrum to Counter Relay Attacks in PKESs
Karim Lounis, Mohammad Zulkernine |
CRiSIS | 2 |
| 2020 | Reliability-based Formation of Cloud Federations Using Game TheoryabstractCloud federation is one form of the cloud computing model that supports numerous types of applications through collaboration between different service providers. Cloud federation enables providers to offer more efficient services to customers by sharing their computing and storage resources. However, the reliability of cloud can be degraded if the federation is formed and executed in an unreliable fashion. In this paper, we propose a reliability-based cloud federation model. We evaluate the reliability of different service providers using our evaluation approach and then model the federation process as a hedonic coalition formation game based on a reliability-driven utility function. Our proposed federation formation algorithm enables service providers to cooperate while considering the reliability of the infrastructure and refrain from cooperating with unreliable systems. Our evaluation shows that the providers will be able to form acceptable federations through our algorithm while preserving or enhancing the reliability of their services in a reasonable amount of time. A. B. M. Bodrul Alam, Talal Halabi, Anwar Haque, Mohammad Zulkernine |
GLOBECOM | 4 |
| 2020 | Multi-Objective Interdependent VM Placement Model based on Cloud Reliability EvaluationabstractVirtual Machine (VM) placement is considered as one of the crucial problems in Cloud Computing environments. From the perspective of Cloud Service Providers (CSPs), finding the optimal VM placement strategy is often related to optimal resource utilization, revenue maximization, and energy efficiency. However, to ensure the continuity of customer services, CSPs should also consider the reliability of deployed applications when placing VMs on their infrastructures. Existing research in this area either do not focus on the Cloud reliability evaluation aspect or do not account for the trade-off between reliability and performance in the VM placement process. In this paper, we propose a multi-objective placement model for interdependent VMs in the Cloud that considers both reliability and workload. Reliability in our model is quantitatively evaluated through a set of metrics that we propose. The model involves an Integer Linear Programming problem that aims at maximizing the reliability of the Cloud while minimizing network delay. A multi-objective genetic algorithm is then used to solve the problem heuristically. The proposed model introduces a level of flexibility and its parameters could be adjusted depending on the requirements of the infrastructure and services. The results show that our model achieves high Cloud reliability and allows to effectively control the trade-off between reliability and Quality of Service. A. B. M. Bodrul Alam, Talal Halabi, Anwar Haque, Mohammad Zulkernine |
ICC | 4 |
| 2020 | Optimizing Virtual Machine Migration in Multi-CloudsabstractCloud computing is susceptible to failures. Allocating Virtual machine (VM) in a reliable fashion is considered as one of the crucial problems in Cloud computing environment. Most researchers choose the optimal VM allocation based on resource utilization and cost minimization. However, to protect the reputation of cloud providers, service reliability should be addressed appropriately. In this paper, we propose a Markov-based failure prediction model to anticipate the failure of Cloud servers. Our model anticipates a deteriorating server state based on historical data. Server reliability prediction is then integrated into a VM re-allocation approach in a Multi-Cloud setting to optimize fault tolerance by maximizing Cloud reliability while reducing communication delay. The optimization problem is solved optimally and heuristically using the Artificial Bee Colony (ABC) algorithm. The results show that our model enhances reliability and minimizes communication delay between the VMs following service migration. A. B. M. Bodrul Alam, Talal Halabi, Anwar Haque, Mohammad Zulkernine |
ISNCC | 4 |
| 2020 | A Game-Theoretic Approach for Distributed Attack Mitigation in Intelligent Transportation SystemsabstractIntelligent Transportation Systems (ITS) play a vital role in the development of smart cities. They enable various road safety and efficiency applications such as optimized traffic management, collision avoidance, and pollution control through the collection and evaluation of traffic data from Road Side Units (RSUs) and connected vehicles in real time. However, these systems are highly vulnerable to data corruption attacks which can seriously influence their decision-making abilities. Traditional attack detection schemes do not account for attackers’ sophisticated and evolving strategies and ignore the ITS’s constraints on security resources. In this paper, we devise a security game model that allows the defense mechanism deployed in the ITS to optimize the distribution of available resources for attack detection while considering mixed attack strategies, according to which the attacker targets multiple RSUs in a distributed fashion. In our security game, the utility of the ITS is quantified in terms of detection rate, attack damage, and the relevance of the information transmitted by the RSUs. The proposed approach will enable the ITS to mitigate the impact of attacks and increase its resiliency. The results show that our approach reduces the attack impact by at least 20% compared to the one that fairly allocates security resources to RSUs indifferently to attackers’ strategies. Talal Halabi, Omar Abdel Wahab 0001, Mohammad Zulkernine |
NOMS | 3 |
| 2020 | LaaCan: A Lightweight Authentication Architecture for Vehicle Controller Area Network
Syed Akib Anwar Hridoy, Mohammad Zulkernine |
SecureComm (2) | 2 |
| 2020 | Exploiting Race Condition for Wi-Fi Denial of Service AttacksabstractWi-Fi is a wireless communication technology that has been around since the late nineties. Nowadays, it is the most adopted wireless technology in various IoT (Internet of Things) applications. Although Wi-Fi security has significantly improved throughout the past years, it is still lagging behind. Many vulnerabilities exist allowing attackers to generate different types of attacks. These attacks can breach the authentication, confidentiality, and data integrity of Wi-Fi networks. In terms of attack impact, attacks on availability have a higher impact. In fact, breaching nowadays systems does not only result in data corruption but may also result in the loss of human lives. Therefore, more consideration should be brought to attacks on availability. In this paper, we present three attacks on Wi-Fi availability. These attacks cause a denial of service on Wi-Fi users by preventing them from connecting to a legitimate network. We adopt the evil twin scheme and exploit a race condition-based vulnerability to generate the attacks. Also, we propose countermeasures to fix the exploited vulnerability and mitigate the attacks. Karim Lounis, Mohammad Zulkernine |
SIN | 2 |
| 2020 | Vehicle Software Engineering (VSE): Research and PracticeabstractThe Internet of Things (IoT) is shaping the future of the automotive industry. Grounded on the advances in everything from sensors, electronic controllers, artificial intelligence, data analytics, to network connectivity, intelligent connected autonomous vehicles (CAVs) have become the essence in IoT applications. The software in CAVs lies at the core of this digital transformation. Faulty software remains the main reason behind the vast number of safety recalls and reputation damage witnessed recently in the automotive industry. The uniqueness of CAVs originates challenges for vehicle software engineering (VSE) that render traditional models and practical solutions for software development ineffective and inapplicable. Despite the raised necessity to adopt a software engineering model that can handle these challenges, there is a lack of studies recognizing the importance of VSE. This article presents an in-depth and comprehensive analysis to perceive the existing software engineering processes detailing their strengths and limitations in the context of CAVs. It also reviews current practical software solutions, including standards, tools, languages, and research efforts to understand the evolution, trends, and current practice in this article area. This article will enable automakers and software providers to better assess and differentiate among the existing software engineering processes and current practical solutions for vehicle software system development. Hence, they would be able to adopt a VSE model and follow best practices that can better meet their challenging needs. Lama Moukahal, Marwa Elsayed, Mohammad Zulkernine |
IEEE Internet Things J. | 3 |
| 2019 | STPSA 2019 Welcome MessageabstractPresents the introductory welcome message from the conference proceedings. May include the conference officers' congratulations to all involved with the conference event and publication of the proceedings record. Sheikh Iqbal Ahamed, Mohammad Zulkernine, Hossain Shahriar, Hongmei Chi |
COMPSAC (2) | 2 |
| 2019 | CSKES: A Context-Based Secure Keyless Entry SystemabstractRemote keyless entry has been widely used on access control systems. These systems, in particular, Passive Keyless Entry and Start systems (PKES), allow drivers automatically unlock their vehicles by standing within one meter of the vehicle while carrying a key fob. Traditional key fobs adopt the RFID (Radio-Frequency IDentification) wireless communication technology. Yet, due to the restricted processing capacity of the key fobs and the vulnerabilities of RFID technology, these systems are subject to relay attack. In this paper, we propose a Context-based Secure Keyless Entry System (CSKES) that adopts BLE (Blue-tooth Low Energy) as a wireless communication technology and utilizes multiple context-based physical security features, namely, RSSI (Receiving Signal Strength Indicator), RTT (Round-Trip Time), GPS (Global Positioning System) coordinates, and Wi-Fi access point lists, to precisely identify the close proximity of a vehicle to its corresponding key fob. This multi-feature proximity identification system is highly efficient to mitigate classic relay attacks. We first introduce the implementation of the proposed system. Then we evaluate the system performance using three classification models with a dataset collected from normal and abnormal use cases. The results show that the proposed Context-based Secure Keyless Entry System demonstrates great efficiency in identifying physical proximity and preventing classic relay attack. Juan Wang 0016, Karim Lounis, Mohammad Zulkernine |
COMPSAC (1) | 3 |
| 2019 | Security Features for Proximity VerificationabstractProximity identification has been widely used on various applications. These applications provide users with convenience and efficiency, however, they are vulnerable to various attacks, such as skimming, eavesdropping, and relay attacks. Modern mobile devices are equipped with sophisticated sensors and receivers to facilitate the process of proximity verification by collecting and comparing information retrieved from the environment. In this paper, we propose multiple physical security features which are accessible through smart devices, namely, RSSI (Receiving Signal Strength Indicator), round-trip time, GPS (Global Positioning System) coordinates, and Wi-Fi access point lists, to precisely identify the close proximity of two devices. These security features are highly efficient to provide proof of physical proximity. We first evaluate each physical security feature individually, through real-life experiments, to demonstrate their efficacy in identifying environment characteristics. Then, we evaluate the performance of each security feature using Wilcoxon test. The results show that the proposed security features are effective in identifying physical proximity and can be combined for better accuracy. Juan Wang 0016, Karim Lounis, Mohammad Zulkernine |
COMPSAC (2) | 3 |
| 2019 | WPA3 Connection Deprivation Attacks
Karim Lounis, Mohammad Zulkernine |
CRiSIS | 2 |
| 2019 | Securing Vehicle ECU Communications and Stored DataabstractNowadays, the automobile industry is integrating many new features into vehicles. To provide these features, various electronic systems are being added. These systems are coordinated by different ECUs (Electronic Control Unit). Vehicle ECUs are internally connected through multiple communication buses. Any ECU connected to the bus can read or send data to other ECUs. As a result, if an adversary can compromise one of the ECUs, then the adversary will be able to access and exploit the data of other important ECUs. Moreover, an adversary can modify the stored data of an important ECU, if it is compromised. To solve these problems, we propose the use of symmetric key cryptography and elliptic curve-based Public Key Encryption (PKE) for ensuring confidentiality and the use of digital signature for ensuring integrity and authenticity. In addition, we propose the adoption of an identity-based access control to control the communication permissions. We also introduce a Blockchain-inspired mechanism to secure data stored in ECUs. Finally, we integrate a watcher to monitor the stored data and report if it is modified. We implement our concept using the ARM architecture-based Raspberry Pi Board and show that our approach can improve security in ECU communications and the watcher reports when an ECU data is modified. Md Swawibe Ul Alam, Shahrear Iqbal, Mohammad Zulkernine, Clifford Liem |
ICC | 3 |
| 2019 | Trust-Based Cooperative Game Model for Secure Collaboration in the Internet of VehiclesabstractThe Internet of Vehicles (IoV) is an emerging computing paradigm that delivers intelligent transportation services. In an IoV system, the legitimacy, reliability, and accuracy of circulating data have a direct impact on decisions and operations, and eventually, public safety and economy. In this paper, we design a decentralized secure collaboration scheme that protects the vehicles in the IoV environment against the attacks on data integrity. First, the trustworthiness of the vehicles is computed based on their experience acquired from direct interactions using a Bayesian inference model. Then, based on the established trust relationships between the vehicles, we present a vehicular coalition formation approach that incorporates a hedonic cooperative game model, which aims at preventing malicious or faulty vehicles from joining benign vehicular collaborative communities. Simulation results show that the proposed scheme is highly resilient to data alteration and corruption attacks. The scheme also demonstrates to be scalable, and will ultimately allow the IoV entities and platform to derive optimal operative decisions on the fly. Talal Halabi, Mohammad Zulkernine |
ICC | 2 |
| 2019 | Bad-token: denial of service attacks on WPA3abstractWPA3 (Wi-Fi Protected Access 3) is a certification that augments its predecessor WPA2 with protection mechanisms, such as resistance against password dictionary attacks through SAE (Simultaneous Authentication of Equals) handshake, MFP (Management Frame Protection) against management frame spoofing, and forward secrecy to prevent an attacker from decrypting old packets if it manages to crack the network key in the future. The mechanism is still under implementation by various device vendors. WPA3-capable devices are supposed to be on the market by the end of this year (2019) or early next year (2020). In this work, we describe a vulnerability that we have discovered in WPA3 authentication protocol. This vulnerability, named bad-token, can be exploited by an attacker in a race condition to cause a denial of service to Wi-Fi clients. The attacker sends fake authentication messages that contain a bad token (WPA3 authentication confirm value) during the WPA3 authentication and prevents legitimate clients from connecting to a WPA3 network. We also present two denial of service attacks related to WPA2, but can be inherited by WPA3. We start by presenting the WPA3-SAE mechanism and then introduce the bad-token vulnerability. We implement an attack that exploits the vulnerability using the Linux software utilities hostapd-2.7 and wpa_supplicant-2.7 on Raspberry Pis and show the impact of the attack on a legitimate WPA3 network. We provide a countermeasure to mitigate the attack. Finally, we present the two WPA2-related attacks that can occur on WPA3 if certain security measures are not applied. We experimentally show the feasibility of these two attacks and propose countermeasures to mitigate them and direct device vendors to better implement security in their future devices. Karim Lounis, Mohammad Zulkernine |
SIN | 2 |
| 2019 | Towards a Security Architecture for Protecting Connected Vehicles from MalwareabstractVehicles are becoming increasingly connected to the outside world. We can connect our devices to the vehicle's infotainment system and internet is being added as a functionality. Therefore, security is a major concern as the attack surface has become much larger than before. Consequently, attackers are creating malware that can infect vehicles and perform life-threatening activities. For example, a malware can compromise vehicle ECUs and cause unexpected consequences. Hence, ensuring the security of connected vehicle software and networks is extremely important to gain consumer confidence and foster the growth of this emerging market. In this paper, we propose a characterization of vehicle malware and a security architecture to protect vehicle from these malware. The architecture uses multiple computational platforms and makes use of the virtualization technique to limit the attack surface. There is a real-time operating system to control critical vehicle functionalities and multiple other operating systems for non-critical functionalities (infotainment, telematics, etc.). The security architecture also describes groups of components for the operating systems to prevent malicious activities and perform policing (monitor, detect, and control). We believe this work will help automakers guard their systems against malware and provide a clear guideline for future research. Shahrear Iqbal, Anwar Haque, Mohammad Zulkernine |
VTC Spring | 3 |
| 2019 | Offering security diagnosis as a service for cloud SaaS applications
Marwa Elsayed, Mohammad Zulkernine |
J. Inf. Secur. Appl. | 2 |
| 2018 | Message from the STPSA 2018 Workshop OrganizersabstractPresents the introductory welcome message from the conference proceedings. May include the conference officers' congratulations to all involved with the conference event and publication of the proceedings record. Sheikh Iqbal Ahamed, Mohammad Zulkernine |
COMPSAC (2) | 2 |
| 2018 | Connection Dumping Vulnerability Affecting Bluetooth Availability
Karim Lounis, Mohammad Zulkernine |
CRiSIS | 2 |
| 2018 | CREM: A Cloud Reliability Evaluation ModelabstractReliability analysis of cloud is not a trivial task due to the complexity and scalability of cloud-based systems. This paper proposes a novel model for evaluating cloud reliability in an effective manner. To provide an appropriate evaluation model, this paper also outlines a classification strategy for cloud failures and considers several types of failures from different domains of cloud environment to properly evaluate the reliability. The effectiveness and applicability of the proposed evaluation model has been demonstrated through simulation results. The results show that execution stage failures have more influence on the cloud reliability than the request processing stage failures. A. B. M. Bodrul Alam, Anwar Haque, Mohammad Zulkernine |
GLOBECOM | 3 |
| 2018 | A Context-Aware Privacy Scheme for Crisis SituationsabstractParticipatory sensing allows individuals and groups to contribute to an application using their handheld sensor devices. Data collected from participants including their location, time, contacts, etc. are vital to the accuracy of the application but are considered private to the participants. The design of a successful participatory sensing application must consider the challenge of the accuracy-privacy trade-off. In more critical situations when a crisis occurs, however, the accuracy-privacy trade-off becomes more complex. When a participant is at risk, data accuracy becomes more important than participant's privacy. In this paper, we propose a Context-Aware Privacy (CAP) scheme. CAP aims to provide privacy- preserved data to authorized recipients based on the status of participants. Depending on the recipient category, their role and policies enforced, a different level of participants' private data may be received. Experimental results show that the CAP scheme achieves a high level of privacy protection in safe areas. In risk areas/situations the scheme achieves a higher level of data accuracy than existing privacy schemes. Mohannad A. Alswailim, Hossam S. Hassanein, Mohammad Zulkernine |
GLOBECOM | 3 |
| 2018 | Protecting Internet users from becoming victimized attackers of click-fraudabstractAbstract Internet users are often victimized by malicious attackers. Some attackers infect and use innocent users' machines to launch large‐scale attacks without the users' knowledge. One of such attacks is the click‐fraud attack. Click‐fraud happens in pay‐per‐click ad networks where the ad network charges advertisers for every click on their ads. Click‐fraud has been proved to be a serious problem for the online advertisement industry. In a click‐fraud attack, a user or an automated software clicks on an ad with a malicious intent and advertisers need to pay for those valueless clicks. Among many forms of click‐fraud, botnets with the automated clickers are the most severe ones. In this study, we present a method for detecting automated clickers from the user side. The proposed method to fight click‐fraud, FCFraud, can be integrated into the desktop and smart device operating systems. Since most modern operating systems already provide some kind of antimalware service, our proposed method can be implemented as a part of the service. We believe that an effective protection at the operating system level can save billions of dollars of the advertisers. Experiments show that FCFraud is 99.6% (98.2% in mobile ad library–generated traffic) accurate in classifying ad requests from all user processes and it is 100% successful in detecting clickbots in both desktop and mobile devices. We implement a cloud backend for the FCFraud service to save battery power in mobile devices. The overhead of executing FCFraud is also analyzed and we show that it is reasonable for both the platforms. Shahrear Iqbal, Mohammad Zulkernine, Fehmi Jaafar, Yuan Gu |
J. Softw. Evol. Process. | 2 |
| 2017 | TRUST-CAP: A Trust Model for Cloud-Based ApplicationsabstractCloud computing provides an opportunity for individuals and organizations to extend their capabilities by offering elastic computing resources. Trust is a major challenge in cloud computing. With trust, cloud users (trustees) can select the best available resources from cloud service providers (trustors) who in turn can evaluate users' behaviors and recommend users to other services. In this paper, we propose a generic TRUST model for Cloud-based APplications (TRUST-CAP) that consists of four components: integrity, access control, availability, and privacy. TRUST-CAP ensures the achievement of security services against common existing attacks including Man-At-The-End (MATE) attacks. In TRUST-CAP, we highlight the required functions that should exist in a trust model for cloud users, service providers, and in-between communication medium. TRUST-CAP can be used for various IoT applications. Eslam G. AbdAllah, Mohammad Zulkernine, Yuan Xiang Gu, Clifford Liem |
COMPSAC (2) | 2 |
| 2017 | Message from SEPT 2017 Organizing CommitteeabstractPresents the introductory welcome message from the conference proceedings. May include the conference officers' congratulations to all involved with the conference event and publication of the proceedings record. Katsuyoshi Iida, Mohammad Zulkernine |
COMPSAC (1) | 2 |
| 2017 | A Participant Contribution Trust Scheme for Crisis Response SystemsabstractWhen a crisis occurs, an immediate response by rescue personnel is crucial. Decisions for a rescue plan are based solely on data about the crisis from the location. It stands to reason that increasing the amount of such data will result in a faster, efficient rescue response. To make this possible, a crisis response system accepts inputs from people near the crisis via their handheld sensor devices such as smartphones and tablets through a participatory sensing system. However, receiving data from the public could potentially result in corrupted and inaccurate data that will negatively impact the rescue plans. Given that risk, assessing the accuracy of the participant's data contribution becomes essential. In this paper, we present a Participant Contribution Trust (PCT) scheme. PCT aims to provide the crisis response system only with the trusted accurate contributions. The steps involved in filtering the contributions include splitting the crisis area into sectors, comparing the contributions with other intra- and inter-sector contributions and confirming the accuracy of the sensed data. Our experimental results show that PCT has a high detection rate for eliminating inaccurate contributions resulting in the delivery of the most accurate data to the crisis response system. Mohannad A. Alswailim, Hossam S. Hassanein, Mohammad Zulkernine |
GLOBECOM | 3 |
| 2017 | Defending Application Cache Integrity of Android Runtime
Mohammad Zulkernine, Phil Eisen, Clifford Liem |
ISPEC | 2 |
| 2017 | Droid Mood Swing (DMS): Automatic Security Modes Based on Contexts
Shahrear Iqbal, Mohammad Zulkernine |
ISC | 2 |
| 2017 | Detecting DNS Tunneling Using Ensemble Learning
Saeed Shafieian, Mohammad Zulkernine |
NSS | 3 |
| 2016 | IFCaaS: Information Flow Control as a Service for Cloud SecurityabstractWith the maturity of service-oriented architecture (SOA) and Web technologies, web services have become critical components of Software as a Service (SaaS) applications in cloud ecosystem environments. Most SaaS applications leverage multi-tenant data stores as a back end to keep and process data with high agility. Although these technologies promise impressive benefits, they put SaaS applications at risk against novel as well as prevalent attack vectors. This security risk is further magnified by the loss of control and lack of security enforcement over sensitive data manipulated by SaaS applications. An effective solution is needed to fulfill several requirements originating in the dynamic and complex nature of such applications. Inspired by the rise of Security as a Service (SecaaS) model, this paper introduces "Information Flow Control as a Service (IFCaaS)". IFCaaS lays the foundation of cloud-delivered IFC-based security analysis and monitoring services. As an example of the adoption of the IFCaaS, this paper presents a novel framework that addresses the detection of information flow vulnerabilities in SaaS applications. Our initial experiments show that the framework is a viable solution to protect against data integrity and confidentiality violations leading to information leakage. Marwa Elsayed, Mohammad Zulkernine |
ARES | 2 |
| 2016 | Message from the SEPT Organizing CommitteeabstractPresents the introductory welcome message from the conference proceedings. May include the conference officers' congratulations to all involved with the conference event and publication of the proceedings record. Bhavani Thuraisingham, Dianxiang Xu, Hiroki Takakura, Mohammad Zulkernine, Elisa Bertino |
COMPSAC | 4 |
| 2016 | A Reputation System to Evaluate Participants for Participatory SensingabstractParticipatory sensing is an approach to data collection that offers individuals and groups the opportunity to participate in an application using their sensor devices. Receiving contributions from multiple individuals may result however, in corrupted and inaccurate sensed data. Therefore, it becomes important to be able to have enough knowledge about each participant in order to evaluate their contributions and trustworthiness. In this paper, we present a Reputation System to Evaluate Participants (RSEP). The RSEP, starts with grouping participants based on their contributions, and then selects the highest group value based on its participant reputation values. The RSEP filters the sensed data to separate out the most accurate contributions that enhance the purpose of the participatory sensing applications. Experimental results show that the proposed RSEP has a high accuracy level in evaluating and selecting participant contributions. Mohannad A. Alswailim, Hossam S. Hassanein, Mohammad Zulkernine |
GLOBECOM | 3 |
| 2016 | DACPI: A decentralized access control protocol for information centric networkingabstractCurrent Internet architecture is becoming inadequate for new requirements of highly scalable and efficient distribution of contents. Information Centric Networking (ICN) is one of the alternatives for the Next Generation Internet (NGI), which focuses mainly on contents. In-network caching is one of the major attributes of ICN, which allows contents to be cached in any ICN node. Any user can access ICN contents from different distributed locations. This attribute maximizes the problem of unauthorized access to ICN contents. In this paper, we propose a Decentralized Access Control Protocol for ICN architectures (DACPI). In this protocol, fewer public messages are needed for access control enforcement between ICN subscribers and ICN nodes than the existing access control protocols. DACPI depends on ICN self-certifying naming scheme. We perform security analysis on DACPI for the following attacks: man-in-the-middle, forward security, replay attacks, integrity, and privacy violations. According to the security analysis, DACPI prevents unauthorized access to ICN contents with fewer messages passed. Eslam G. AbdAllah, Mohammad Zulkernine, Hossam S. Hassanein |
ICC | 2 |
| 2016 | Analysing vulnerability reproducibility for Firefox browserabstractFixing some security failures are difficult because they cannot be easily reproduced. To address Hardly Reproducible Vulnerabilities (HRVs), security experts spend a significant amount of time, effort, and budget. Sometimes they do not succeed in the reproduction step and ignore some security failures. The exploitation of a vulnerability due to its irreproducibility may cause severe consequences. An efficient solution is to explore the behaviour of both hardly and easily reproducible security issues at the code level. We use linear regression techniques to build models based on the classical software complexity metrics and a set of attributes related to the environment of the system. The results show that the considered metrics and the vulnerability types do not have significant linear correlations with each other. Also, predicting the HRV-prone parts of large systems is a great help for security experts to focus their effort on the top-ranked vulnerable files. After identifying the suitable indicators based on linear regression, different machine learning techniques such as Random Forest, Logistic Regression, C4.5 Decision Tree, and Naive Bayes are employed to build HRV prediction models. The Random Forest technique achieves the precision of 82% and recall of 84% to classify vulnerable files into HRV-prone or non HRV-prone files. We believe that the results encourage the use of software metrics for vulnerability prediction in some projects. Maryam Davari, Mohammad Zulkernine |
PST | 2 |
| 2016 | Intrusion detection in a private network by satisfying constraintsabstractWith the advancement of newer technologies, the frequency of malicious attacks is growing rapidly. Even private networks without external connections cannot hide from these attacks. Constant monitoring of the network is a vital element of an organization's security system. Among many monitoring techniques, network behavior analysis has become a common practice. Restricted private networks are characterized by a limited number of protocols. The normal traffic pattern of a network can be modeled as network constraints. Violation of any of these constraints indicates that an intrusion has occurred. This paper presents a novel framework to detect intrusions in a private network. We illustrate the framework with ten significant constraints on the real-time publish, subscribe and internet group management protocols. We present how the framework evaluates these constraints against traffic from an experimental network to prevent attacks. Md Siam Hasan, Ali ElShakankiry, Thomas R. Dean, Mohammad Zulkernine |
PST | 4 |
| 2016 | SAM: A secure anti-malware framework for the smartphone operating systemsabstractSmartphones have become an integral part of our daily life. Businesses now offer services through smartphones. Users also store sensitive personal information on their smartphones and perform financial transactions. Consequently, security attacks on smartphone platforms have also increased significantly. Traditional desktop anti-virus software are not very effective in smartphones due to the restrictive security model and they are heavily dependent on their definition updates. In this paper, we propose a Secure Anti-Malware framework (SAM) for smartphone operating systems to prevent malicious activities. The core idea of the framework resembles a smart city. The framework acts as the government of the city and treats the applications as citizens. It has components to enforce laws (prevent) and perform policing (monitor and control). It also provides APIs to aid anti-virus software and third-party applications to leverage the functionalities of the framework. Our goal is to design an operating system framework that hinders malicious activities and thus protects user resources. Shahrear Iqbal, Mohammad Zulkernine |
WCNC | 2 |
| 2016 | Evaluating the impact of design pattern and anti-pattern dependencies on changes and faults
Fehmi Jaafar, Yann-Gaël Guéhéneuc, Sylvie Hamel, Foutse Khomh, Mohammad Zulkernine |
Empir. Softw. Eng. | 5 |
| 2016 | Special issue on High Assurance Systems Engineering
Peter J. Clarke, Mohammad Zulkernine |
Softw. Qual. J. | 2 |
| 2015 | Message from SEPT Symposium Organizing CommitteeabstractPresents a listing of the Symposium organizing committee. Bhavani Thuraisingham, Dianxiang Xu, Hiroki Takakura, Mohammad Zulkernine, Elisa Bertino |
COMPSAC | 4 |
| 2015 | FPGuard: Detection and Prevention of Browser Fingerprinting
Amin FaizKhademi, Mohammad Zulkernine, Komminist Weldemariam |
DBSec | 2 |
| 2014 | TabsGuard: A Hybrid Approach to Detect and Prevent Tabnabbing Attacks
Hana Fahim-Hashemi, Mohammad Zulkernine, Komminist Weldemariam |
CRiSIS | 2 |
| 2014 | Countermeasures for Mitigating ICN Routing Related DDoS Attacks
Eslam G. AbdAllah, Mohammad Zulkernine, Hossam S. Hassanein |
SecureComm (2) | 2 |
| 2014 | Effective detection of vulnerable and malicious browser extensions
Hossain Shahriar, Komminist Weldemariam, Mohammad Zulkernine, Thibaud Lutellier |
Comput. Secur. | 3 |
| 2014 | Software control flow error detection and correlation with system performance deviation
Atef Shalan, Mohammad Zulkernine |
J. Comput. Syst. Sci. | 2 |
| 2014 | Special issue on "Trustworthy Software Systems for the Digital Society"
Xiaoying Bai, Atilla Elçi, Mohammad Zulkernine |
J. Syst. Softw. | 3 |
| 2014 | Preventing Cache-Based Side-Channel Attacks in a Cloud EnvironmentabstractCloud computing is a unique technique for outsourcing and aggregating computational hardware needs. By abstracting the underlying machines cloud computing is able to share resources among multiple mutually distrusting clients. While there are numerous practical benefits to this system, this kind of resource sharing enables new forms of information leakage such as hardware side-channels. In this paper, we investigate the usage of CPU-cache based side-channels in the cloud and how they compare to traditional side-channel attacks. We go on to demonstrate that new techniques are necessary to mitigate these sorts of attacks in a cloud environment, and specify the requirements for such solutions. Finally, we design and implement two new cache-based side-channel mitigation techniques, implementing them in a state-of-the-art cloud system, and testing them against traditional cloud technology. Michael Misiu Godfrey, Mohammad Zulkernine |
IEEE Trans. Cloud Comput. | 2 |
| 2013 | A Server-Side Solution to Cache-Based Side-Channel Attacks in the CloudabstractAs Cloud services become more common place, recent work have uncovered vulnerabilities unique to Cloud systems. Specifically, the paradigm promotes a risk of information leakage across virtual machine isolation via side-channels. In this paper, we investigate the current state of side-channel vulnerabilities involving the CPU cache, and identify the shortcomings of traditional defenses in a Cloud environment. We explore why solutions to non-Cloud cache-based side-channels cease to work in Cloud environments, and develop a mitigation technique applicable for Cloud security. Applying this solution to a canonical Cloud environment, we demonstrate the validity of this Cloud-specific, cache-based side-channel mitigation technique. Furthermore, we show that it can be implemented as a server-side approach to improve security without inconveniencing the client. Finally, we conduct a comparison of our solution to the current state-of-the-art. Michael Misiu Godfrey, Mohammad Zulkernine |
IEEE CLOUD | 2 |
| 2013 | EINSPECT: Evolution-Guided Analysis and Detection of Malicious Web PagesabstractMost existing work to thwart malicious web pages capture maliciousness via discriminative artifacts, learn a model, and detect by leveraging static and/or dynamic analysis. Unfortunately, there is a two-sided evolution of the artifacts of web pages. On one hand, cybercriminals constantly revamp attack payloads in malicious web pages. On the other hand, benign web pages evolve to improve content rendering and interaction with users. Consequently, the onceprecise detection techniques suffer from limitations to cope with the evolution, resulting in malicious web pages that escape detection. In this paper, we present EINSPECT, an evolution-aware and learning-based approach to address evolution of web page artifacts to more precisely analyze and detect malicious web pages. EINSPECT continuously tunes its detection models to automatically decide the best interplay of features and learning algorithms to embrace the evolution of web page artifacts into the analysis and detection. We have implemented and evaluated our approach and the results show that EINSPECT is able to improve the effectiveness of analysis and detection ofmalicious web pages while aligning the detection models with the continuous evolution of web page artifacts. Birhanu Eshete, Adolfo Villafiorita, Komminist Weldemariam, Mohammad Zulkernine |
COMPSAC | 4 |
| 2013 | Software Assurance: What Should We Do Next?abstractSummary form only given, as follows. A complete record of the panel discussion was not made available for publication as part of the conference proceedings. Our day to day activities are almost completely dependent on software. It is rare to find an automated system which is not software controlled. Software defects are a serious threat to our society costing billions of dollars to our economy every year. As a result, software assurance is critical to the assurance of our daily lives. To achieve software assurance, we have to trade-off among a number of interdependent and complementary attributes such as reliability, security, privacy, availability, safety, usability, and many others. Software systems are becoming (ultra) larger and more complex day by day as they interact with many other software and hardware systems, while new paradigms and computing environments such as Cloud and mobile are becoming more common. Therefore, it is extremely important to assess the software assurance processes and techniques to identify our priorities: Are we there yet? Where are we now? Finally, what should we do next or what things should we do differently? This panel will try to answer these questions. Four panelists will deliver their opinion on the issues in achieving software assurance as mentioned above. They will emphasize on different phases and aspects of a software life cycle. Prof. Crnkovic will talk about software design for reliability, Prof. Tse will present his view on the challenges in testing modern software systems, Prof. McMillin will share his experience of software deployment in a cyber-physical environment, and finally Prof. Uehara will provide his thoughts on software security issues. Each panelist will make a 8-10 minute introductory statement on their position on this topic, and then the panel will open up for questions and answers. Mohammad Zulkernine |
COMPSAC | 1 |
| 2013 | Protecting Web Browser Extensions from JavaScript Injection AttacksabstractVulnerable web browser extensions can be used by an attacker to steal users' credentials and lure users into leaking sensitive information to unauthorized parties. Current browser security models and existing JavaScript security solutions are inadequate for preventing JavaScript injection attacks that can exploit such vulnerable extensions. In this paper, we present a runtime protection mechanism based on a code randomization technique coupled with a static analysis technique to protect browser extensions from JavaScript injection attacks. The protection is enforced at runtime by distinguishing malicious code from the randomized extension code. We implemented our protection mechanism for the Mozilla Firefox browser and evaluated it on a set of vulnerable and non-vulnerable Firefox extensions. The evaluation results indicate that our approach can be a viable solution for preventing attacks on JavaScript-based browser extensions. In designing and implementing our approach, we were also able to reduce false positives and achieve maximum backward compatibility with existing extensions. Anton Barua, Mohammad Zulkernine, Komminist Weldemariam |
ICECCS | 2 |
| 2013 | Runtime Prediction of Failure Modes from System Error LogsabstractPredicting potential failure occurrences during runtime is important to achieve system resilience and avoid hazardous consequences of failures. Existing failure prediction techniques in software systems involve forecasting failure counts, effects, and occurrences. Most of these techniques predict failures that may occur in future runtime intervals and only few techniques predict them at runtime. However, they do not estimate the failure modes and they require extensive instrumentation of source code. In this paper, we provide an approach for predicting failure occurrences and modes during system runtime. Our methodology utilizes system error log records to craft runtime error-spread signature. Using system error log history, we determine a predictive function (estimator) for each failure mode based on these signatures. This estimator can be used to predict a failure mode eventuality measure (a probability of failure mode occurrence) from system error log during system runtime. An experimental evaluation using PostgreSQL opensource database is provided. Our results show high accuracy of failure occurrence and mode predictions. Atef Shalan, Mohammad Zulkernine |
ICECCS | 2 |
| 2012 | A Comparative Study of Software Security Pattern ClassificationsabstractSoftware security patterns can be the building blocks of secure software systems. They provide reliable solutions for recurring security problems. The rapid increase in the number of security patterns creates difficulty in the selection of appropriate security patterns for particular security problems. Researchers provide several classification schemes based on unique selection criteria for choosing appropriate security patterns. These schemes are very helpful for software designers to select security patterns for particular security problems. In this paper, we survey various security pattern classification schemes. Further, we compare and contrast these classification schemes using their classification objectives, attributes, dimensions, and quality metrics. The result is helpful for selecting a suitable classification scheme based on the desirable classification attributes and quality metrics. The right selection of classification improves the capability of software designers to select appropriate security patterns for recurring security problems in a specific security context. Aleem Khalid Alvi, Mohammad Zulkernine |
ARES | 2 |
| 2012 | Mutation Testing of Event Processing QueriesabstractEvent processing queries are intended to process continuous event streams. These queries are partially similar to traditional SQL queries, but provide the facilities to express rich features (e.g., pattern expression, sliding window of length and time). An error while implementing a query may result in abnormal program behaviors and lost business opportunities. Moreover, queries can be generated with unsanitized inputs and the structure of intended queries might be altered. Thus, a tester needs to test the behavior of queries in presence of malicious inputs. Mutation testing has been found to be effective to assess test suites quality and generating new test cases. Unfortunately, there is no effort to perform mutation testing of event processing queries. In this work, we propose mutation-based testing of event processing queries. We choose Event Processing Language (EPL) as our case study and develop necessary mutation operators and killing criteria to generate high quality event streams and malicious inputs. Our proposed operators modify different features of EPL queries (pattern expression, windows of length and time, batch processing of events). We develop an architecture to generate mutants for EPL and perform mutation analysis. We evaluate our proposed EPL mutation testing approach with a set of developed benchmark containing diverse types EPL queries. The evaluation results indicate that the proposed operators and mutant killing criteria are effective to generate test cases capable of revealing anomalous program behaviors (e.g., event notification failure, delay of event reporting, unexpected event), and SQL injection attacks. Moreover, the approach incurs less manual effort and can complement other testing approach such as random testing. Lorena Gutiérrez-Madroñal, Hossain Shahriar, Mohammad Zulkernine, Juan José Domínguez-Jiménez, Inmaculada Medina-Bulo |
ISSRE | 3 |
| 2012 | Trustworthiness testing of phishing websites: A behavior model-based approach
Hossain Shahriar, Mohammad Zulkernine |
Future Gener. Comput. Syst. | 2 |
| 2012 | Guest Editorial: Special section on software reliability and security
Jongmoon Baik, Fabio Massacci, Mohammad Zulkernine |
Inf. Softw. Technol. | 3 |
| 2011 | Security Monitoring of Components Using Aspects and Contracts in WrappersabstractThe re-usability and modularity of components reduce the cost and complexity of the software design. It is difficult to predict run-time scenarios covering all possible circumstances to ensure that the components are fully compatible with the system. Given that, monitoring run-time behaviours of components presents a close view of the component qualities. The existing monitoring approaches either implement applications with built-in monitoring features, or observe the external resources and events to predict the status of the components. In this paper, we propose an approach to monitor the runtime behaviours of components using aspect-oriented wrappers and contracts. We design monitoring wrappers to encapsulate the monitored components. We use contracts to define the mutual obligations of two interacting components. The policies implemented in contracts are woven into component wrappers as separate aspect modules. If the component contains any flaws or vulnerabilities, the wrappers can monitor some behaviours and prevent failures propagating into the wrapped components and the rest of the system. This approach assures that the system is running in a safe environment with the erroneous behaviours detected appropriately. We conducted experiments on the run-time monitoring of SQL Injection, Cross Site Scripting attacks, and access control policies. The results show that the framework is very flexible to impose separate policies as aspects on component wrappers without the modifications of the underlying components. Mohammad Zulkernine |
COMPSAC | 2 |
| 2011 | A Natural Classification Scheme for Software Security PatternsabstractSoftware security patterns are a proven solution for recurring security problems. Security pattern catalogs are increasing rapidly. This creates difficulty in selecting appropriate software security patterns for a particular recurring security problem. There are several classification schemes to organize software security patterns. Every classification scheme has unique selection criteria for choosing a security pattern. However, no classification scheme considers security flaws, which is the root cause of software security vulnerabilities. In this paper, we provide a natural classification scheme for software security patterns. Our classification scheme is associated with software lifecycle phases. Security flaws are incorporated in the classification of software security patterns with security objectives in the requirement phase, security properties in the design phase, and attack patterns in the implementation phase. Furthermore, we enhance the existing security pattern template with classification parameters. Aleem Khalid Alvi, Mohammad Zulkernine |
DASC | 2 |
| 2011 | A Connection-Based Signature Approach for Control Flow Error DetectionabstractControl Flow Errors (CFEs) are major impairments of software system correctness. These CFEs can be caused by operational faults with respect to the execution environment of a software system. Several techniques are proposed to monitor the control flow using signature-based approaches. These techniques partition a software program into branch-free blocks and assign a unique signature for each block. They detect CFEs by comparing the runtime signatures of these blocks with pre-computed signatures based on the program Control Flow Graph (CFG). Unfortunately, branch-free block partitioning does not completely include all the program connections. Consequently, these techniques may fail to detect some invalid transitions due to lack of signatures associated with those missing connections. In this paper, we propose a connection-based signature approach for CFE detection. We first describe our connection-based signature structure in which we partition the program components into Connection Implementation Blocks (CIBs). Each CIB is associated with a Connection-based CFG (CCFG) to represent the control structure of its code segment. We present our control flow monitor structure and CFE checking algorithm using these CCFGs. The error detection approach is evaluated using PostgreSQL open-source database. The results show that this technique is capable of detecting CFEs in different software versions with variable numbers of randomly injected faults. Atef Mohamed, Mohammad Zulkernine |
DASC | 2 |
| 2011 | S2XS2: A Server Side Approach to Automatically Detect XSS AttacksabstractCross site scripting (XSS) vulnerabilities are widespread in web-based programs. Server side detection of suspected contents can mitigate XSS exploitations early. Unfortunately, existing serve side approaches impose modification of server and client side environments. In this paper, we develop an automated framework to detect XSS attacks at the server side based on the notion of boundary injection and policy generation. Boundaries mark content generation locations in server script code. We derive expected benign features of dynamic contents that are matched during response page generation to detect attacks. We develop a prototype tool to automatically insert boundaries and generate policies for JSP programs. We evaluate the approach with four JSP programs. The results indicate that the approach detects most of the well known XSS attacks. Moreover, the false positive rates vary between zero and 5.2%. The approach suffers from negligible runtime overhead. Hossain Shahriar, Mohammad Zulkernine |
DASC | 2 |
| 2011 | A Fuzzy Logic-Based Buffer Overflow Vulnerability AuditorabstractBuffer overflow (BOF) vulnerabilities in programs might result in unwanted consequences such as neighboring data corruption and execution of arbitrary code. To assure that implemented programs are free from BOF, auditing is a well known quality assurance method. Today, there exist few tools that aid an auditor to partially automate the task of BOF vulnerability auditing. These tools provide too many warnings that are often similar types to be dealt with and do not allow an auditor providing his/her opinions to better interpret the generated warnings. To improve the quality of warnings, we propose a fuzzy logic-based BOF vulnerability auditor. Our contribution includes the development of crisp BOF vulnerability characteristics and the corresponding fuzzy sets. We apply Mamdani style fuzzy inferences by developing sets of rules to infer the presence of BOF warning present in programs. Moreover, for the overall assessment of a program's vulnerability level, we design a multi-unit fuzzy logic-based system. The auditor has been evaluated with benchmark programs that contain BOF vulnerabilities. The results show that our auditor performs better compared to the existing auditing tools. The auditor can be used as a basis to assure the quality of a program against BOF vulnerabilities. Hossain Shahriar, Mohammad Zulkernine |
DASC | 2 |
| 2011 | Server Side Detection of Content Sniffing AttacksabstractContent sniffing attacks occur if browsers render non-HTML files embedded with malicious HTML contents or JavaScript code as HTML files. The rendering of these embedded contents might cause unwanted effects such as the stealing of sensitive information through the execution of malicious JavaScript code. The primary source of these attacks can be stopped if the uploading of malicious files can be prevented from the server side. However, existing server side content sniffing attack detection approaches suffer from a number of limitations. First, file contents are checked only to a fixed amount of initial bytes whereas attack payloads might reside anywhere in the file. Second, these approaches do not provide any mechanism to assess the malicious impact of the embedded contents on browsers. This paper addresses these issues by developing a server side content sniffing attack detection mechanism based on content analysis using HTML and JavaScript parsers and simulation of browser behavior via mock download testing. We have implemented our approach in a tool that can be integrated in web applications written in various languages. In addition, we have developed a benchmark suite for the evaluation purpose that contains both benign and malicious files. We have evaluated our approach on three real world PHP programs suffering from content sniffing vulnerabilities. The evaluation results indicate that our approach can secure programs against content sniffing attacks by successfully preventing the uploading of malicious files. Anton Barua, Hossain Shahriar, Mohammad Zulkernine |
ISSRE | 3 |
| 2011 | Using complexity, coupling, and cohesion metrics as early indicators of vulnerabilities
Istehad Chowdhury, Mohammad Zulkernine |
J. Syst. Archit. | 2 |
| 2011 | Taxonomy and classification of automatic monitoring of program security vulnerability exploitations
Hossain Shahriar, Mohammad Zulkernine |
J. Syst. Softw. | 2 |
| 2010 | Classification of Buffer Overflow Vulnerability MonitorsabstractBuffer overflow is one of the worst program vulnerabilities. Many preventive approaches are applied to mitigate buffer overflow (BOF) vulnerabilities. However, BOF vulnerabilities are still being discovered in programs on a daily basis which might be exploited to crash programs and execute unwanted code at runtime. Monitoring is a popular approach for detecting BOF attacks during program execution and can prevent the consequences of BOF vulnerability exploitations. However, there is no classification of the proposed approaches to understand their common characteristics, objectives, and limitations. In this paper, we classify the current BOF vulnerability monitoring approaches based on the following five characteristics: monitoring objective, program state utilization, implementation mechanism, environmental change, and attack response. The classification will enable researchers to differentiate among existing monitoring approaches. Moreover, it will provide a guideline to choose monitoring approaches suitable for their needs. Hossain Shahriar, Mohammad Zulkernine |
ARES | 2 |
| 2010 | Client-Side Detection of Cross-Site Request Forgery AttacksabstractCross Site Request Forgery (CSRF) allows an attacker to perform unauthorized activities without the knowledge of a user. An attack request takes advantage of the fact that a browser appends valid session information for each request. As a result, a browser is the first place to look for attack symptoms and take appropriate actions. Current browser-based detection methods are based on cross-origin policies that allow white listed third party websites to perform requests to a trusted website. These approaches are not effective if policies are specified incorrectly. Moreover, these approaches do not focus on the detection of stored CSRF attacks where attack payloads reside in trusted web pages. To alleviate these limitations, we present a CSRF attack detection mechanism for the client side. Our approach relies on the matching of parameters and values present in a suspected request with a form's input fields and values that are being displayed on a webpage (visibility). To overcome an attacker's attempt to circumvent form visibility checking, we compare the response content type of a suspected request with the expected content type. We have implemented a prototype plug-in tool for the Firefox browser and evaluated our approach on three real PHP programs vulnerable to CSRF attacks. We have also developed a benchmark test suite containing 134 test cases for emulating CSRF attack requests for the three programs. The evaluation results indicate that our approach can detect most of the common form of reflected and stored CSRF attacks. Moreover, our approach can stop attack requests that include subsets of visible form fields and values. Hossain Shahriar, Mohammad Zulkernine |
ISSRE | 2 |
| 2010 | Assessing Test Suites for Buffer Overflow VulnerabilitiesabstractOver the last few years, numerous vulnerabilities have been reported in software, and successful exploitations of these vulnerabilities have resulted in severe consequences such as denial of services and application state corruptions. Researches have shown that effective quality assurance methods can prevent such consequences when applied during software (or applications) development processes. Software security testing is a popular assurance method in this direction. However, effective testing involves obtaining an effective test suite (or collection of test cases) that can reveal specific faults. Over the last few years, different testing approaches have been applied for revealing vulnerabilities in software. However, only few works have assessed the effectiveness of test suites for revealing vulnerabilities. We believe that bringing the idea of mutation-based assessment of test adequacy for vulnerabilities can help in detecting and removing vulnerabilities proactively. In this work, we apply mutation-based adequate testing for one of the worst vulnerabilities namely buffer overflow (BOF). We propose 16 mutation operators to force the generation of adequate test suites for BOF vulnerabilities. A prototype tool is developed to automatically generate mutants and perform mutation analysis with input test cases. The effectiveness of the operators is evaluated by using several benchmark programs having BOF vulnerabilities, and the results indicate that the proposed operators are effective for testing BOF vulnerabilities. Moreover, we present an analysis to find selective mutation operators for reducing the cost of mutation-based testing of BOF vulnerabilities. Hossain Shahriar, Mohammad Zulkernine |
Int. J. Softw. Eng. Knowl. Eng. | 2 |
| 2009 | On Selecting Appropriate Development Processes and Requirements Engineering Methods for Secure SoftwareabstractTo avoid security vulnerabilities, there are many secure software development efforts in the directions of secure software development life cycle processes, security specification languages, and security requirements engineering processes. In this paper, we compare and contrast various secure software development processes based on a number of characteristics that such processes should have. We also analyze security specification languages with respect to desirable properties of such languages. Furthermore, we identify activities that should be performed in a security requirements engineering process to derive comprehensive security requirements. We compare different security requirements engineering processes based on these activities. Our analysis shows that many of the secure software requirements engineering methods lack some of the desired properties. The comparative study presented in this paper will provide guidelines to software developers for selecting specific methods that will fulfill their needs in building secure software applications. Muhammad Umair Ahmed Khan, Mohammad Zulkernine |
COMPSAC (2) | 2 |
| 2009 | Automatic Testing of Program Security VulnerabilitiesabstractVulnerabilities in applications and their widespread exploitation through successful attacks are common these days. Testing applications for preventing vulnerabilities is an important step to address this issue. In recent years, a number of security testing approaches have been proposed. However, there is no comparative study of these work that might help security practitioners select an appropriate approach for their needs. Moreover, there is no comparison with respect to automation capabilities of these approaches. In this work, we identify seven criteria to analyze program security testing work. These are vulnerability coverage, source of test cases, test generation method, level of testing, granularity of test cases, testing automation, and target applications. We compare and contrast prominent security testing approaches available in the literature based on these criteria. In particular, we focus on work that address four most common but dangerous vulnerabilities namely buffer overflow, SQL injection, format string bug, and cross site scripting. Moreover, we investigate automation features available in these work across a security testing process. We believe that our findings will provide practical information for security practitioners in choosing the most appropriate tools. Hossain Shahriar, Mohammad Zulkernine |
COMPSAC (2) | 2 |
| 2009 | Secure Method Calls by Instrumenting Bytecode with Aspects
Mohammad Zulkernine |
DBSec | 2 |
| 2009 | Towards Model-Based Automatic Testing of Attack Scenarios
Mohammad Zulkernine, Mohammad Feroz Raihan, Gias Uddin 0001 |
SAFECOMP | 1 |
| 2009 | A model-based aspect-oriented framework for building intrusion-aware software systems
Zhi Jian Zhu, Mohammad Zulkernine |
Inf. Softw. Technol. | 2 |
| 2009 | Collaboration through computation: incorporating trust model into service-based software systems
Gias Uddin 0001, Mohammad Zulkernine, Sheikh Iqbal Ahamed |
Serv. Oriented Comput. Appl. | 2 |
| 2008 | An Intrusion-Tolerant Mechanism for Intrusion Detection SystemsabstractIn accordance with the increasing importance of intrusion detection systems (IDS), users justifiably demand the trustworthiness of the IDS. However, sophisticated attackers attempt to disable the IDS before they launch a thorough attack. Therefore, to accomplish its function, an IDS should have some mechanism to guarantee uninterrupted detection service even in the face of IDS component failures due to attacks. In this paper, we propose an intrusion-tolerant mechanism for network intrusion detection systems (NIDS) that employ multiple independent components. The mechanism monitors the detection units and the hosts on which the units reside and enables the IDS to survive component failure due to intrusions. As soon as a failed IDS component is discovered, a copy of the component is installed to replace it and the detection service continues. We implement the intrusion-tolerant mechanism based on the CSI-KNN-based NIDS and evaluate the prototype in the face of component failures. The results demonstrate that the mechanism can effectively tolerate intrusions. Liwei Kuang, Mohammad Zulkernine |
ARES | 2 |
| 2008 | Towards Incorporating Discrete-Event Systems in Secure Software DevelopmentabstractWhen designers and developers create software they often overlook issues related to security. Ideally, protection of the program from illegal usage would be considered at each stage of this program's life cycle. The proposition put forward here is to augment intrusion detection systems (IDSs) and employ them as a tool to support secure software development. Many state-based intrusion detection methods share structural and behavioural similarities with the set of processes known as discrete-event systems (DESs). A common structure for modelling DESs is the deterministic finite-state automaton. There exist several compatible anomaly detection techniques which construct finite- state machine models of normal behaviour through the decomposition of associated data (e.g., system calls, HTTP requests) into sequences of events. This paper proposes the application of decentralized DES theory to formally analyze and enhance these approaches to anomaly detection with misuse prevention. Models of misuse attacks are generated in the same manner as the legal usage representation, then augmented and integrated into the program model to prevent the execution of malicious sequences. The technique described herein simultaneously uses anomaly and misuse approaches to prevent and disable attacks before their completion. Sarah-Jane Whittaker, Mohammad Zulkernine, Karen Rudie |
ARES | 2 |
| 2008 | A Distributed Defense Framework for Flooding-Based DDoS AttacksabstractA flooding-based distributed denial of service (DDoS) attack sends a large amount of unwanted traffic to a victim machine. Existing network-level congestion control mechanisms are inadequate in preventing service quality from deteriorating because of these attacks. We propose a distributed framework to defend against DDoS attacks. It has three major components: detection, traceback, and traffic control. We present the traffic control component in detail in this paper. A distance-based rate limit mechanism is proposed to allow the traffic control component at the victim end request the defense systems at the source end to set up rate limits on the edge routers of the attack source ends. This rate limit mechanism efficiently reduces attack traffic from being forwarded to the victim. We evaluate the DDoS defense framework using the NS2 platform. The results demonstrate that the framework can effectively control attack traffic to sustain quality of service for legitimate traffic compared to the pushback technique. Yonghua You, Mohammad Zulkernine, Anwar Haque |
ARES | 2 |
| 2008 | Message from the STPSA 2008 Workshop OrganizersabstractPresents the introductory welcome message from the conference proceedings. Sheikh Iqbal Ahamed, Mohammad Zulkernine |
COMPSAC | 2 |
| 2008 | STPSA 2008 Workshop OrganizationabstractProvides a listing of current committee members and society officers. Sheikh Iqbal Ahamed, Mohammad Zulkernine |
COMPSAC | 2 |
| 2008 | Quantifying Security in Secure Software Development PhasesabstractSecure software is crucial in todaypsilas software dependent world. However, most of the time, security is not addressed from the very beginning of a software development life cycle (SDLC), and it is only incorporated after the software has been developed. Even when security is considered since the inception of the software development, there is no concrete way to quantify security of an SDLC artifact. This quantification is necessary to know about the security state of an SDLC artifact after each phase of software development. Moreover, this could help the software developers in allocating further resources to increase security and decrease the vulnerabilities in any software. In this paper, we use vulnerability occurrences to calculate a vulnerability index of an SDLC artifact that provides an indication about the existing vulnerabilities. Moreover, we calculate a security index by using the combined potential damage that can be caused due to vulnerabilities. Muhammad Umair Ahmed Khan, Mohammad Zulkernine |
COMPSAC | 2 |
| 2008 | Mutation-Based Testing of Buffer Overflow VulnerabilitiesabstractBuffer overflow (BOF) is one of the major vulnerabilities that leads to non-secure software. Testing an implementation for BOF vulnerabilities is challenging as the underlying reasons of buffer overflow vary widely. Moreover, the existing vulnerability testing approaches do not address the issue of generating adequate test data sets for testing BOF vulnerabilities. In this work, we apply the idea of mutation-based testing technique to generate adequate test data set for BOF vulnerabilities. Our work addresses those BOF vulnerabilities, which are related to an implementation language and its associated libraries. We apply the concept for ANSI C language and its associated libraries. We propose 12 mutation operators to force the generation of adequate test data set for BOF vulnerabilities. The proposed operators are validated by using four open source programs. The results indicate that the proposed operators are effective for testing BOF vulnerabilities. Hossain Shahriar, Mohammad Zulkernine |
COMPSAC | 2 |
| 2008 | Random-Forests-Based Network Intrusion Detection SystemsabstractPrevention of security breaches completely using the existing security technologies is unrealistic. As a result, intrusion detection is an important component in network security. However, many current intrusion detection systems (IDSs) are rule-based systems, which have limitations to detect novel intrusions. Moreover, encoding rules is time-consuming and highly depends on the knowledge of known intrusions. Therefore, we propose new systematic frameworks that apply a data mining algorithm called random forests in misuse, anomaly, and hybrid-network-based IDSs. In misuse detection, patterns of intrusions are built automatically by the random forests algorithm over training data. After that, intrusions are detected by matching network activities against the patterns. In anomaly detection, novel intrusions are detected by the outlier detection mechanism of the random forests algorithm. After building the patterns of network services by the random forests algorithm, outliers related to the patterns are determined by the outlier detection algorithm. The hybrid detection system improves the detection performance by combining the advantages of the misuse and anomaly detection. We evaluate our approaches over the knowledge discovery and data mining 1999 (KDDpsila99) dataset. The experimental results demonstrate that the performance provided by the proposed misuse approach is better than the best KDDpsila99 result; compared to other reported unsupervised anomaly detection approaches, our anomaly detection approach achieves higher detection rate when the false positive rate is low; and the presented hybrid system can improve the overall performance of the aforementioned IDSs. Mohammad Zulkernine, Anwar Haque |
IEEE Trans. Syst. Man Cybern. Part C | 2 |
| 2007 | AsmLSec: An Extension of Abstract State Machine Language for Attack Scenario SpecificationabstractSecurity, one of the most important aspects of software, gets very little attention during the software development life cycle (SDLC). Therefore, the software remains vulnerable to attacks which are handled by issuing patches or service packs by the software vendors. To overcome this problem, researchers have proposed to take security into consideration right from the very beginning of the software development process. However, most specification languages were not designed with an intention for specifying security requirements, and therefore, they lack some features to serve this purpose. As a result, we need suitable specification languages that can be used both for functional specification and security specification. We propose a formal extension of a popular specification language called AsmL (Abstract State Machine Language) for attack descriptions with a view to building secure software. We name the extended language AsmLSec. We present the details of AsmLSec syntax and semantics, describe how to model attacks using its constructs, and present the design and implementation of a compiler that generates attack signatures from the AsmLSec attack specifications. To evaluate the expressive power of AsmLSec, we model attack scenarios based on the benchmark DARPA data sets Mohammad Feroz Raihan, Mohammad Zulkernine |
ARES | 2 |
| 2007 | ACIR: An Aspect-Connector for Intrusion ResponseabstractThe modularization concept behind component-based software (CBS) cannot be applied effectively for cross-cutting concerns such as security. Aspect-oriented programming (AOP) helps in better modularization by identifying cross-cutting concerns and providing a suitable way to separate those concerns. In this paper, we provide an aspect-connector based intrusion response (detection and prevention) architecture for CBS by bringing the concepts of aspects into components. The aspect-connector is named as ACIR (aspect connector for intrusion response). Component interfaces act as join points, and aspects containing pointcuts and advices are defined in ACIR configuration file. Advices applicable to particular pointcuts are two types. Signature advices are used to detect intrusions, and action advices are executed to prevent intrusions. A prototype of this architecture is implemented and evaluated using some intrusions included in the Web application security consortium (WASC) intrusion list. This approach detects and prevents intrusions in CBS while maintaining encapsulation, reusability, and modularity. Gias Uddin 0001, Hossain Shahriar, Mohammad Zulkernine |
COMPSAC (2) | 3 |
| 2007 | Towards an Aspect-Oriented Intrusion Detection FrameworkabstractIn this paper, we propose a framework to develop aspects for intrusion detection. We model attack scenarios using an aspect-oriented unified modeling language (UML) profile. Based on the attack scenario model, the intrusion detection aspects are developed and woven into the target system. The resulting system has the ability to detect the intrusions. The major objective of this work is to invite aspect-oriented software development to the task of detecting intrusions. Zhi Jian Zhu, Mohammad Zulkernine |
COMPSAC (1) | 2 |
| 2007 | The Power of Temporal Pattern Processing in Anomaly Intrusion DetectionabstractA clear deficiency in most of todays anomaly intrusion detection systems (AIDS) is their inability to distinguish between a new form of legitimate normal behavior and a malicious attack based on known previous normal behaviors. This deficiency is known as the lack of generalization ability. The lack of generalization ability of the present AIDS results mainly in two direct consequences. As a first consequence, the current AIDS are capable of detecting neither new sophisticated attacks nor slight variations of known attacks launched against computing systems. The high rate of false positive and false negative alerts generated by the current AIDS is the second consequence. Many research initiatives that utilize machine learning techniques including neural networks have been proposed to overcome the lack of generalization. Unfortunately, most of such research initiatives have intrinsically focused on utilizing static techniques, that perform structural pattern recognition. Temporal pattern processing techniques have not gained much attention in this arena. In this research, we present a novel anomaly intrusion detection system based on recurrent neural networks (RNN) which is a temporal pattern processing technique. We show that RNN can efficiently discriminate novel intrusive behaviors while recognizing new normal behaviors. Thus, they reduce the false positive and negative alarms, and address the lack of generalization problem associated with the current AIDS. The ability of RNN to generalize normal as well as intrusive behavior outperforms Multilayer Perceptron (MLP) neural network, a structural pattern recognition technique, in a significant way. Mohammad Al-Subaie, Mohammad Zulkernine |
ICC | 2 |
| 2007 | Detecting Flooding-Based DDoS AttacksabstractA distributed denial of service (DDoS) attack is widely regarded as a major threat for the current Internet because of its ability to create a huge volume of unwanted traffic. It is hard to detect and respond to DDoS attacks due to large and complex network environments. In this paper, we introduce two distance-based DDoS detection techniques: average distance estimation and distance-based traffic separation. They detect attacks by analyzing distance values and traffic rates. The distance information of a packet can be inferred from the time- to-live (TTL) value of the IP header. In the average distance estimation DDoS detection technique, the prediction of mean distance value is used to define normality. The prediction of traffic arrival rates from different distances is used in the distance-based traffic separation DDoS detection technique. The mean absolute deviation (MAD)-based deviation model provides the legal scope to separate the normality from the abnormality for both the techniques. The results obtained from the NS2-based simulations of the proposed techniques show that the techniques can detect attacks Yonghua You, Mohammad Zulkernine, Anwar Haque |
ICC | 2 |
| 2007 | E-NIPS: An Event-Based Network Intrusion Prediction System
Pradeep Kannadiga, Mohammad Zulkernine, Anwar Haque |
ISC | 2 |
| 2007 | Packet Filtering Based on Source Router Marking and Hop-CountabstractDenial of service (DoS) attacks impose an increasingly growing threat to the Internet These attacks result in wastage of scarce Internet resources and service disruptions. Existing packet filtering schemes are deployable at either source, intermediate or victim networks. In this paper, we propose a hybrid of the source and the victim networks-based packet filtering approach, source router marking and hop-count (SRHC), to detect and filter high-rate traffic flows and IP-spoofing attacks. Packets are marked at the source network based on their arrival rate threshold. At a victim network, the spoofed packets are marked based on the IP source arrival rate using their respective TTL value. Both source and victim networks collaborate to filter high-rate and IP-spoofing attacks. The ns-2 simulator is used to generate attack scenarios. Our simulation results show that the SRHC scheme effectively filters out high-rate and IP-spoofing attack packets, with minimal collateral damage. Kashif Ali, Mohammad Zulkernine, Hossam S. Hassanein |
LCN | 2 |
| 2007 | A software-based trust framework for distributed industrial management systems
Sheikh Iqbal Ahamed, Mohammad Zulkernine, Steven T. Wolfe |
J. Syst. Softw. | 2 |
| 2007 | Intrusion detection aware component-based systems: A specification-based framework
Mohammad Zulkernine |
J. Syst. Softw. | 2 |
| 2006 | A Dependable Device Discovery Approach for Pervasive Computing MiddlewareabstractDistributed applications and middleware services targeted for mobile devices must use device discovery service to provide any kind of service to other devices. Device discovery algorithms developed for wired networks are not suitable for mobile ad-hoc networks of pervasive computing environments. This research proposes a dependable device discovery mechanism for the middleware of the applications consisting of rapidly reconfiguring mobile devices. Our approach offers a comprehensive solution to potential problems that can arise in highly adaptive mobile ad-hoc networks of pervasive computing environments. The approach is robust enough to accommodate the device limitations and rapid changes in the resource strengths of each device in the network. We present three new device discovery algorithms in this paper: a window based broadcasting algorithm, a connectivity based dynamic algorithm, and a policy-based scalable algorithm. The algorithms vary in complexity and efficiency depending upon the pervasive computing applications. We identify the desirable dependability related characteristics of device discovery services and present how our algorithms realize those characteristics. Experimental results are presented to compare and contrast the algorithms. Sheikh Iqbal Ahamed, Mohammad Zulkernine, Suresh Anamanamuri |
ARES | 2 |
| 2006 | A Hybrid Network Intrusion Detection Technique Using Random ForestsabstractIntrusion detection is important in network security. Most current network intrusion detection systems (NIDSs) employ either misuse detection or anomaly detection. However, misuse detection cannot detect unknown intrusions, and anomaly detection usually has high false positive rate. To overcome the limitations of both techniques, we incorporate both anomaly and misuse detection into the NIDS. In this paper, we present our framework of the hybrid system. The system combines the misuse detection and anomaly detection components in which the random forests algorithm is applied. We discuss the advantages of the framework and also report our experimental results over the KDD'99 dataset. The results show that the proposed approach can improve the detection performance of the NIDSs, where only anomaly or misuse detection technique is used. Mohammad Zulkernine |
ARES | 2 |
| 2006 | A Trust Framework for Pervasive Computing EnvironmentsabstractIn this paper, we present a flexible, manageable, and configurable trust scheme for the security of pervasive computing applications. Our intention is to develop a trust framework capable of recognizing the difference between “pure” and “managed” ad hoc network structure, and capable of operating in either situation or a combination of both. Our trust framework will minimize the effects of malicious recommendations related to trust from other devices and have the capability to transfer security functionality from devices with limited computing resources to other secure and powerful devices. The presented framework allows administrators to customize trust-related settings in an effort to create a more secure and functional network. Within our framework, wireless devices are broken down into different categories based upon available resources and desired security functionalities. A device’s categorization determines its security functionalities and interactions with neighboring devices. By using this flexible framework, administrators can customize devices based upon the network’s environment. Steven T. Wolfe, Sheikh Iqbal Ahamed, Mohammad Zulkernine |
AICCSA | 3 |
| 2006 | Efficacy of Hidden Markov Models Over Neural Networks in Anomaly Intrusion DetectionabstractThe timely and accurate detection of novel attacks is a persistent necessity to insure the dependability of information processing systems. Although anomaly intrusion detection systems (AIDSs) have the potential to discover novel attacks, AIDSs suffer from the lack of generalization capability and the presence of high false alarm rates. Many machine learning techniques have been proposed to overcome the lack of generalization in existing AIDSs. Unfortunately, the main stream of these techniques is static techniques that perform structural pattern recognition. Such techniques are not capable of efficiently modeling an essential property of the behaviors of the monitored objects. This property is the sequential relationship between the events of the patterns that constitute the normal and abnormal behaviors. In this research, we show that the sequential relationship between the events of the normal and abnormal behaviors is vital for anomaly detection. Moreover, the techniques that efficiently model this property can build robust AIDSs. To illustrate this reality, we investigate the performance of two different detection techniques: Hidden Markov Models (HMMs), a sequential learning mechanism, and Multilayer Perceptron (MLP) neural network, a structural pattern recognition technique. We demonstrate that the detection of HMMs classifiers outperforms the detection of the MLP classifiers in a noticeable manner. Mohammad Al-Subaie, Mohammad Zulkernine |
COMPSAC (1) | 2 |
| 2006 | Anomaly Based Network Intrusion Detection with Unsupervised Outlier DetectionabstractAnomaly detection is a critical issue in Network Intrusion Detection Systems (NIDSs). Most anomaly based NIDSs employ supervised algorithms, whose performances highly depend on attack-free training data. However, this kind of training data is difficult to obtain in real world network environment. Moreover, with changing network environment or services, patterns of normal traffic will be changed. This leads to high false positive rate of supervised NIDSs. Unsupervised outlier detection can overcome the drawbacks of supervised anomaly detection. Therefore, we apply one of the efficient data mining algorithms called random forests algorithm in anomaly based NIDSs. Without attack-free training data, random forests algorithm can detect outliers in datasets of network traffic. In this paper, we discuss our framework of anomaly based network intrusion detection. In the framework, patterns of network services are built by random forests algorithm over traffic data. Intrusions are detected by determining outliers related to the built patterns. We present the modification on the outlier detection algorithm of random forests. We also report our experimental results over the KDD'99 dataset. The results show that the proposed approach is comparable to previously reported unsupervised anomaly detection approaches evaluated over the KDD' 99 dataset. Mohammad Zulkernine |
ICC | 2 |
| 2006 | Bridging the gap: software specification meets intrusion detectorabstractThere exist a number of Intrusion Detection Systems (IDSs) that detect computer attacks based on some defined attack scenarios. The attack scenarios or security requirements in some of these IDSs are specified in attack specification languages which are separate from software specification languages. The use of two different languages for software specification and attack specification may generate redundant and conflicting requirements. The advantage of using the same language for both functional specifications and attacks specifications is that software designers can address the two different issues without learning the two types of languages. We present a method of using a software specification language called Abstract State Machine Language (AsmL) as an attack specification language for the open source IDS Snort. This work provides AsmL users an IDS that they can use without knowing how to write Snort rules. We automatically translate attack scenarios written in AsmL into Snort rules with context information. The original Snort is modified so that it can use the rules automatically generated by the translator. Adding context information to Snort rules improves the detection capability of Snort. To show the efficacy of our presented approach, we have built a prototype and evaluated it using a number of well-known attack scenarios. Mathew Graves, Mohammad Zulkernine |
PST | 2 |
| 2005 | Detecting Intrusions Specified in a Software Specification LanguageabstractTo protect software against malicious activities, organizations are required to monitor security breaches. Intrusion detection systems (IDS) are those kinds of monitoring tools that have gained a considerable amount of popularity, A number of specification-based IDSs have been proposed, where security requirements or attack scenarios are specified using some languages. Currently, attack specification languages are being deployed for describing security requirements. Use of two different languages for software specification and security specification invites a number of unwanted but complicated issues, such as duplication of requirements specification effort as well as the existence of redundant and conflicting requirements. In this paper, we present an intrusion detection technique that uses a formal software specification language called abstract state machine language (AsmL) for the specification of security requirements. We present a framework, and develop the algorithm for the IDS that interprets the AsmL attack scenario specifications in order to detect intrusions. Moreover, we discuss case studies where the presented intrusion detection system is used to detect attacks. Mohammad Feroz Raihan, Mohammad Zulkernine |
COMPSAC (1) | 2 |
| 2005 | Network Intrusion Detection using Random Forests
Mohammad Zulkernine |
PST | 2 |
| 2005 | A Software Implementation of a Genetic Algorithm Based Approach to Network Intrusion DetectionabstractWith the rapid expansion of Internet in recent years, computer systems are facing increased number of security threats. Despite numerous technological innovations for information assurance, it is still very difficult to protect computer systems. Therefore, unwanted intrusions take place when the actual software systems are running. Different soft computing based approaches have been proposed to detect computer network attacks. This paper presents a genetic algorithm (GA) based approach to network intrusion detection, and the software implementation of the approach. The genetic algorithm is employed to derive a set of classification rules from network audit data, and the support-confidence framework is utilized as fitness function to judge the quality of each rule. The generated rules are then used to detect or classify network intrusions in a real-time environment. Unlike most existing GA-based approaches, because of the simple representation of rules and the effective fitness function, the proposed method is easier to implement while providing the flexibility to either generally detect network intrusions or precisely classify the types of attacks. Experimental results show the achievement of acceptable detection rates based on benchmark DARPA data sets on intrusions, while no other complementary techniques or relevant heuristics are applied. Ren Hui Gong, Mohammad Zulkernine, Purang Abolmaesumi |
SNPD | 2 |
| 2005 | DIDMA: A Distributed Intrusion Detection System Using Mobile AgentsabstractThe widespread proliferation of Internet connections has made current computer networks more vulnerable to intrusions than before. In network intrusions, there may be multiple computing nodes that are attacked by intruders. The evidences of intrusions have to be gathered from all such attacked nodes. An intruder may move between multiple nodes in the network to conceal the origin of attack, or misuse some compromised hosts to launch the attack on other nodes. To detect such intrusion activities spread over the whole network, we present a new intrusion detection system (IDS) called distributed intrusion detection using mobile agents (DIDMA). DIDMA uses a set of software entities called mobile agents that can move from one node to another node within a network, and perform the task of aggregation and correlation of the intrusion related data that it receives from another set of software entities called the static agents. Mobile agents reduce network bandwidth usage by moving data analysis computation to the location of the intrusion data, support heterogeneous plat-forms, and offer a lot of flexibility in creating a distributed IDS. DIDMA utilizes the above-mentioned beneficial features offered by mobile agent technology and addresses some of the issues with centralized IDS models. The detailed architecture and implementation of a prototype of DIDMA are described. It has been tested using some well-known attacks and performances have been corn-pared with centralized IDS models. Pradeep Kannadiga, Mohammad Zulkernine |
SNPD | 2 |
| 2005 | Routeguard: an intrusion detection and response system for mobile ad hoc networksabstractAs wireless networks increase in pervasiveness and popularity, it is becoming more important to have an effective intrusion detection and response solution. Wireless ad hoc networks are particularly vulnerable to denial of service attacks (DoS) due to their open decentralized architecture, highly dynamic topology and shared wireless medium in which they exist. One of the primary concerns with respect to ad hoc networks is to provide secure communication among mobile nodes in a hostile environment. In this paper, we propose a novel intrusion detection and response system called Routeguard. Routeguard employs a smart and smooth architecture in order to effectively discover malicious nodes and then proceeds to protect the network. The presented intrusion detection scheme produces a more natural system, which is more capable of dealing with malicious or suspected nodes. Simulation results demonstrate that this scheme improves network throughput by smartly classifying the nodes into different categories depending on their current actions and previous history. Ahmed Hasswa 0001, Mohammad Zulkernine, Hossam S. Hassanein |
WiMob (3) | 2 |
| 2005 | Towards automatic monitoring of component-based software systems
Mohammad Zulkernine, Rudolph E. Seviora |
J. Syst. Softw. | 1 |
| 2002 | A Compositional Approach to Monitoring Distributed SystemsabstractThis paper proposes a specification-based monitoring approach for automatic run-time detection of software errors and failures of distributed systems. The specification is assumed to be expressed in communicating finite state machines based formalism. The monitor observes the external I/O and partial state information of the target distributed system and uses them to interpret the specification. The approach is compositional as it achieves global monitoring by combining the component-level monitoring. The core of the paper describes the architecture and operations of the monitor The monitor includes several independent mechanisms, each tailored to detecting specific kinds of errors or failures. Their operations are described in detail using illustrative examples. Techniques for dealing with nondeterminism and concurrency issues in monitoring a distributed system are also discussed with respect to the considered model and specification. A case study describing the application of the prototype monitor to an embedded system is presented. Mohammad Zulkernine, Rudolph E. Seviora |
DSN | 1 |
| 2002 | Assume-Guarantee Algorithms for Automatic Detection of Software Failures
Mohammad Zulkernine, Rudolph E. Seviora |
IFM | 1 |
| 2001 | Assume-Guarantee Supervisor for Concurrent SystemsabstractDespite rigorous use of model checking, testing, and other technological innovations in software development there exists faults which elude those detection efforts and do not surface until the software is operational. These faults may lead to serious software failures (deviation of actual behavior from the desired one). Existing software failure detectors for concurrent systems are not compositional, and hence suffer from the state explosion problem. We present a compositional approach for automatic failure detection of concurrent programs specified as a collection of communi-cating finite state machines. The failure detector described in this paper is called assume-guarantee supervisor. The su-pervisor simultaneously observes the input/output and sta-ble states of the target system, interprets the specification, and reports the discrepancies between these two as failures. We formalize an assume-guarantee paradigm for supervi-sion, and provide a generic failure detection algorithm. We also describe the architecture and operation of a failure de-tection tool which employs the above model. This tool can be employed for online software failure detection in the op-erational stage of a system. 1 Mohammad Zulkernine, Rudolph E. Seviora |
IPDPS | 1 |